Sekit CSF · Family
Logging & Monitoring
24 controls in 8 topics, each seen through the policy, process and technical lenses.
Policy
RCF-0202Alerting & triage6 mappingsThe company formally defines how security alerts are prioritised, assigned and responded toRCF-0196Centralized logging5 mappingsThe company formally requires that security-relevant events from all systems are collected in a central locationRCF-0211Detection engineering5 mappingsThe company formally develops and maintains detection logic tailored to its own environment and threat profileRCF-0208Log protection & retention4 mappingsThe company formally defines how long logs must be retained and how they must be protected from tamperingRCF-0199SIEM use cases5 mappingsFormal detection scenarios are defined to identify known threats using collected log dataRCF-0214Telemetry coverage6 mappingsThe company formally identifies which systems must generate security telemetry and ensures there are no blind spotsRCF-0193Time sync4 mappingsThe company formally requires all systems to synchronise their clocks to a trusted time sourceRCF-0205UEBA/behavior analytics5 mappingsThe company formally deploys behavioural analysis to identify anomalous activity that rules-based detection misses
Process
RCF-0203Alerting & triage6 mappingsSecurity alerts are consistently triaged within defined timeframes and false positives are tuned outRCF-0197Centralized logging5 mappingsLog sources are consistently onboarded to the central logging platform and gaps are identified and closedRCF-0212Detection engineering5 mappingsDetection rules are consistently developed, tested and refined using threat intelligence and past incidentsRCF-0209Log protection & retention4 mappingsLog retention policies are consistently enforced and log integrity is verifiedRCF-0200SIEM use cases5 mappingsSIEM detection rules are consistently reviewed and updated to address emerging threatsRCF-0215Telemetry coverage6 mappingsTelemetry coverage is consistently assessed and gaps in visibility are remediatedRCF-0194Time sync4 mappingsTime synchronisation is consistently configured and verified across all systems and infrastructureRCF-0206UEBA/behavior analytics4 mappingsBehavioural baselines are consistently maintained and anomalous deviations are investigated
Technical
RCF-0204Alerting & triage5 mappingsTechnical tools route alerts to the correct team, track response times and escalate unacknowledged alertsRCF-0198Centralized logging5 mappingsTechnical tools aggregate logs from all systems into a centralised platform for analysis and retentionRCF-0213Detection engineering4 mappingsTechnical tools support detection rule development, testing and deployment at scale across the monitoring platformRCF-0210Log protection & retention3 mappingsTechnical controls write logs to tamper-evident storage and enforce retention periods automaticallyRCF-0201SIEM use cases4 mappingsSIEM correlation rules automatically detect threat patterns and generate alerts for investigationRCF-0216Telemetry coverage5 mappingsTechnical tools map telemetry coverage across the environment and alert when expected sources stop sending dataRCF-0195Time sync4 mappingsTechnical controls enforce NTP synchronisation and alert when system clocks drift beyond acceptable thresholdsRCF-0207UEBA/behavior analytics4 mappingsUEBA tools automatically build user and entity behaviour profiles and alert on statistically significant deviations
This family in ISO/IEC 27001:2022
Every framework item the family's controls map to, most-connected first — grouped by Sekit CSF family, never by the framework's own index.
This family in NIST CSF 2.0
This family in ISO/IEC 42001:2023 — Annex A
Ask Sekura: “What evidence proves Logging & Monitoring?”
Also via MCP, free with account