SekitCrosswalk
ISO/IEC 27001:2022 · derived mapping target

A.8.16Monitoring activities

Monitor networks, systems and applications for unusual behavior that could indicate a security incident, and act on what you find.

Mapped from the Sekit CSF

The Sekit controls that cover this requirement, lens by lens.

RCF-0009Risk assessment · TechnicalrelatedFeeding risk assessments with real technical data draws on the same monitoring activity A.8.16 requires, but serves risk analysis rather than the detection function itself.RCF-0015Exception management · TechnicalrelatedMaking approved exceptions visible to monitoring and pairing them with compensating controls extends A.8.16's monitoring scope to cover accepted risk, not standard activity.RCF-0021Metrics & reporting · TechnicalrelatedA dashboard of security metrics reports on what monitoring already detected, downstream of the detection activity A.8.16 requires.RCF-0027Third-party risk management · TechnicalsupportsLogging and reviewing third-party account activity is a specific application of the network and system monitoring A.8.16 requires, focused on external access.RCF-0033Control testing program · TechnicalrelatedScheduled vulnerability scans, backup verification and configuration drift checks test that controls work, a related discipline to A.8.16's monitoring for signs of an active security incident.RCF-0036Issues management · TechnicalrelatedTracking security issues with timestamps and escalation manages what monitoring surfaces, but the ticket record is follow-up paperwork, not the detection activity A.8.16 performs.RCF-0048Service inventory · TechnicalsupportsMonitoring the availability and security posture of critical external services, including uptime and certificate expiry, is a direct instance of the monitoring A.8.16 requires.RCF-0051Ownership & custodians · TechnicalenablesRecording asset ownership so alerts route to the right person automatically is the precondition that makes A.8.16's monitoring alerts actionable rather than ignored.RCF-0054Criticality tagging · TechnicalenablesTagging assets with criticality ratings that prioritize alert handling gives A.8.16's monitoring a way to triage what matters most first.RCF-0060Shadow IT discovery · TechnicalsupportsContinuously detecting unauthorized devices and unsanctioned cloud services is monitoring activity aimed squarely at the unusual behavior A.8.16 wants surfaced.RCF-0072Privileged access management · TechnicalsupportsWatching privileged sessions and alerting on unusual administrative activity is monitoring focused on the accounts capable of the most damage, central to A.8.16.RCF-0087Access reviews (recertification) · TechnicalrelatedGenerating access listings for periodic review depends on identity data rather than the real-time behavioral monitoring A.8.16 is primarily about.RCF-0137API security · ProcesssupportsMonitoring APIs once live, alongside designing and testing them against requirements, extends A.8.16's monitoring activity to application-layer traffic.RCF-0144DevSecOps governance · TechnicalrelatedAggregating pipeline security findings into one view reports on development-time monitoring, adjacent to but not the same as the system monitoring A.8.16 covers.RCF-0147Configuration baselines · TechnicalsupportsContinuously comparing device settings to the approved baseline and flagging drift is monitoring activity that detects the unusual configuration changes A.8.16 targets.RCF-0149EDR/anti-malware · ProcesssupportsKeeping endpoint protection current and investigating its alerts within an agreed timeframe operationalizes the monitoring response A.8.16 requires.RCF-0150EDR/anti-malware · TechnicalsupportsAn EDR agent watching endpoint behavior in real time and containing threats automatically applies A.8.16's monitor-and-act objective to endpoints, one slice of the networks, systems and applications A.8.16 covers.RCF-0158Removable media control · ProcesssupportsWatching for removable media use and following up unapproved devices is monitoring activity focused on a specific unusual-behavior pattern A.8.16 cares about.RCF-0174Firewall management · TechnicalsupportsA firewall with change logging and alerts on rule modifications monitors network boundary behavior, flagging rule edits that could open an unauthorized access path.RCF-0176Secure DNS · ProcesssupportsReviewing DNS records and resolver reports on a recurring basis is monitoring aimed at catching tampering or bypass, an unusual-behavior pattern A.8.16 targets.RCF-0179Email security · ProcesssupportsTriaging reported suspicious emails and tuning filters from what is learned is monitoring activity applied to the email channel, within A.8.16's scope.RCF-0195Time sync · TechnicalenablesAlerting automatically when a clock drifts beyond threshold keeps timestamps trustworthy, a precondition for A.8.16's monitoring to correlate events correctly across systems.RCF-0198Centralized logging · TechnicalenablesAggregating logs from across the environment into one searchable platform is the data foundation A.8.16's monitoring and detection activity is built on.RCF-0199SIEM use cases · PolicyenablesDocumenting which threat scenarios the monitoring platform must detect turns detection coverage into a deliberate choice, the scoping A.8.16 depends on.RCF-0200SIEM use cases · ProcesssupportsReviewing and updating detection rules on a recurring cycle keeps A.8.16's monitoring able to catch new threats rather than only what it caught last year.RCF-0201SIEM use cases · TechnicalsupportsCorrelation rules that combine events across sources and raise alerts ready for investigation are one detection mechanism inside A.8.16, which also requires acting on what monitoring finds.RCF-0203Alerting & triage · ProcesssupportsTriaging alerts within defined timeframes and tuning out false positives is the operational discipline that makes A.8.16's monitoring produce signal instead of noise.RCF-0204Alerting & triage · TechnicalsupportsRouting alerts to the right responder and escalating when unacknowledged closes the loop between A.8.16's detection and an actual human response.RCF-0205UEBA/behavior analytics · PolicyenablesDeciding deliberately what behavioral analysis should watch and who acts on it is the scoping decision that makes A.8.16's anomaly monitoring workable rather than noise.RCF-0206UEBA/behavior analytics · ProcesssupportsKeeping behavioral baselines current and investigating flagged deviations is the ongoing work that makes A.8.16's anomaly-based monitoring effective rather than theoretical.RCF-0207UEBA/behavior analytics · TechnicalsupportsProfiling normal behavior and alerting on deviations like improbable sign-in travel is monitoring squarely aimed at the unusual activity A.8.16 wants detected.RCF-0211Detection engineering · PolicyenablesCommitting to build detection logic tailored to the company's own environment is the governance basis that gives A.8.16's monitoring detection tuned to real risk.RCF-0212Detection engineering · ProcesssupportsDeveloping, testing and refining detection rules from threat intelligence and past incidents keeps A.8.16's monitoring capability current against real threats.RCF-0213Detection engineering · TechnicalsupportsVersioning and testing detection rules before deploying them across the monitoring platform supports reliable, non-disruptive delivery of A.8.16's detection logic.RCF-0215Telemetry coverage · ProcessenablesAssessing telemetry coverage on a recurring basis and closing gaps ensures A.8.16's monitoring has data to watch in the first place.RCF-0216Telemetry coverage · TechnicalsupportsAlerting automatically when an expected log source goes quiet catches the blind spot that would otherwise let A.8.16's monitoring miss unusual behavior silently.RCF-0234Exposure management · TechnicalsupportsContinuous monitoring of the external attack surface, alerting when a new or vulnerable service appears, is monitoring activity aimed directly at what A.8.16 requires visibility into.RCF-0261IR plan · TechnicalsupportsTooling that detects suspicious activity on endpoints and accounts and supports rapid containment is the detect-and-act pairing A.8.16 describes.RCF-0264Roles & communications · TechnicalrelatedAn out-of-band coordination channel supports the incident response that follows detection, adjacent to but not part of the monitoring activity A.8.16 covers.RCF-0267Playbooks · TechnicalrelatedEmbedding playbook steps into operational tooling guides the response after monitoring detects something, downstream of A.8.16's detection function.RCF-0273Notification & escalation · TechnicalrelatedAutomated notification when an incident is declared supports timely escalation after detection, adjacent to A.8.16's monitor-and-detect scope.RCF-0276Tabletop exercises · TechnicalrelatedRealistic incident simulation tooling tests the response process, not the ongoing monitoring A.8.16 requires day to day.RCF-0279Post-incident review (lessons learned) · TechnicalrelatedRetaining incident data for post-incident review analyzes what monitoring already caught, rather than being the detection activity A.8.16 covers.RCF-0297Supply chain continuity · TechnicalsupportsMonitoring the operational status of critical suppliers so outages surface before customers report them extends A.8.16's monitoring to third-party dependencies.RCF-0338CSPM posture · ProcesssupportsReviewing cloud configuration findings on a recurring schedule and fixing them within deadlines operationalizes A.8.16's monitoring for cloud misconfigurations.RCF-0339CSPM posture · TechnicalsupportsContinuous scanning of cloud accounts for insecure configurations with alerts is posture management scoped to the cloud, one piece of the monitoring across networks, systems and applications A.8.16 requires.RCF-0344Cloud logging · ProcessenablesKeeping audit logging switched on in every cloud account and reviewing it regularly gives A.8.16's cloud monitoring the data it needs to detect anything.RCF-0347Workload protection · ProcesssupportsChecking running cloud workloads against the security standard and investigating deviations is monitoring activity focused on cloud runtime behavior, within A.8.16's scope.RCF-0348Workload protection · TechnicalsupportsWatching cloud workloads for threats at runtime and enforcing policy is the technical monitoring mechanism A.8.16 requires, applied to cloud infrastructure.RCF-0354SaaS security configuration · TechnicalsupportsContinuously comparing SaaS settings against a baseline and alerting on drift is monitoring aimed at unusual configuration changes across the SaaS estate A.8.16 covers.RCF-0399Executive briefings · TechnicalrelatedA leadership dashboard reports what monitoring already found, informing decisions rather than performing the detection A.8.16 requires.RCF-0408SRE/Resilience practices · TechnicalsupportsMonitoring agreed reliability indicators and triggering automated actions when thresholds are breached applies A.8.16's monitor-and-act pattern to service resilience.RCF-0410Availability management · ProcesssupportsContinuously monitoring critical service availability and recording every incident is a direct application of the monitoring A.8.16 requires, focused on uptime.RCF-0411Availability management · TechnicalrelatedAutomated uptime monitoring against targets flags availability degradation rather than the unusual behavior that could indicate a security incident A.8.16 targets, though both rely on continuous monitoring discipline.RCF-0413Capacity & performance mgmt · ProcessrelatedReviewing resource use and acting before it causes outages monitors performance trends, adjacent to but distinct from the security-focused monitoring A.8.16 targets.RCF-0414Capacity & performance mgmt · TechnicalrelatedMonitoring that tracks resource use and scales capacity automatically addresses capacity risk, a related but separate concern from the unusual-behavior detection A.8.16 covers.RCF-0416Problem management · ProcessrelatedTracking known problems to resolution reduces recurring incidents that monitoring detects, but is remediation work rather than the monitoring activity itself.RCF-0417Problem management · TechnicalrelatedSurfacing incident patterns from ticketing and monitoring data supports root-cause analysis downstream of the detection A.8.16 performs.RCF-0426Patch/compensating controls (ICS) · TechnicalsupportsCompensating controls including monitoring focused on unpatchable devices apply A.8.16's monitoring discipline to production systems that cannot be patched directly.RCF-0429IR for ICS · TechnicalsupportsTooling that can observe and contain incidents in the production network without disruption extends A.8.16's monitor-and-respond capability into OT environments.

NIST CSF 2.0 counterparts

Reached through the Sekit CSF controls both map to — a mapping, not a formal equivalence.

ISO/IEC 42001:2023 — Annex A counterparts

Cyber Essentials counterparts

Evidence that proves this control

What an auditor, or Sekit's evidence engine, asks for.

Endpoint protection console
The antivirus or advanced protection (EDR) tool installed on devices, and proof that it is deployed and up to date across the fleet.
Logging and monitoring configuration
How the company collects and keeps activity logs from its systems, and how security alerts are generated and handled.
Zero Trust and advanced detection
The advanced network-security and detection approaches: Zero Trust access (never trust by default), behavior analytics (UEBA), and custom detection engineering.
From the Sekit evidence catalog

In practice

Monitoring only earns its name when someone looks at the alerts. What works for an SME: centralize logs into a SIEM or lightweight equivalent, define a short list of detection use cases that matter for the business rather than importing every vendor default, and commit to triaging alerts within a set timeframe so genuine signals do not drown in noise. EDR on endpoints catching and auto-containing threats does more real-world work than a large rule library nobody tunes. Auditors ask what the last three alerts were, how fast they were triaged, and whether anyone tuned out the recurring false positive that made the team stop looking.

Common gaps

The SIEM ingests logs from most systems but detection rules were never customized beyond vendor defaults, so genuine threats specific to the business go unnoticed.
Alerts pile up in a queue with no defined triage timeframe, and the team has started ignoring a noisy rule that fires on legitimate activity.
Endpoint detection is deployed but nobody reviews its alerts on a regular cadence, so containment only happens when someone notices by chance.

Questions your auditor will ask

How quickly are security alerts triaged after they fire?
Alerts are triaged within a defined timeframe set in the monitoring process, with escalation rules ensuring an unacknowledged alert reaches someone else automatically.
What detection scenarios does your monitoring cover, and is that a deliberate list?
A documented list of threat scenarios drives the detection rules, reviewed and updated on a recurring cycle rather than relying only on vendor defaults.
How would you detect an unauthorized device or cloud service connected to your systems?
Continuous discovery tooling scans for unauthorized devices on the network and unsanctioned cloud services handling company data, flagging anything unapproved.
What happens automatically when endpoint detection spots suspicious behavior?
The EDR agent isolates or blocks the threat in real time without waiting for a human, and the alert is logged for review.

Where regulation demands it

NIS2 art. 3.2 requires monitoring and logging capable of detecting anomalies. ENS op.mon.3 expects continuous surveillance of systems to catch unusual activity.

Related controls

Via the shared Sekit CSF topic, not the framework's own index.

Ask Sekura: “What evidence proves A.8.16?”
Also via MCP, free with account