Sekit CSF · Familia
Logging & Monitoring
24 controles en 8 temas, cada uno visto a través de las lentes de política, proceso y técnica.
Política
RCF-0202Alerting & triage6 mapeosThe company formally defines how security alerts are prioritised, assigned and responded toRCF-0196Centralized logging5 mapeosThe company formally requires that security-relevant events from all systems are collected in a central locationRCF-0211Detection engineering5 mapeosThe company formally develops and maintains detection logic tailored to its own environment and threat profileRCF-0208Log protection & retention4 mapeosThe company formally defines how long logs must be retained and how they must be protected from tamperingRCF-0199SIEM use cases5 mapeosFormal detection scenarios are defined to identify known threats using collected log dataRCF-0214Telemetry coverage6 mapeosThe company formally identifies which systems must generate security telemetry and ensures there are no blind spotsRCF-0193Time sync4 mapeosThe company formally requires all systems to synchronise their clocks to a trusted time sourceRCF-0205UEBA/behavior analytics5 mapeosThe company formally deploys behavioural analysis to identify anomalous activity that rules-based detection misses
Proceso
RCF-0203Alerting & triage6 mapeosSecurity alerts are consistently triaged within defined timeframes and false positives are tuned outRCF-0197Centralized logging5 mapeosLog sources are consistently onboarded to the central logging platform and gaps are identified and closedRCF-0212Detection engineering5 mapeosDetection rules are consistently developed, tested and refined using threat intelligence and past incidentsRCF-0209Log protection & retention4 mapeosLog retention policies are consistently enforced and log integrity is verifiedRCF-0200SIEM use cases5 mapeosSIEM detection rules are consistently reviewed and updated to address emerging threatsRCF-0215Telemetry coverage6 mapeosTelemetry coverage is consistently assessed and gaps in visibility are remediatedRCF-0194Time sync4 mapeosTime synchronisation is consistently configured and verified across all systems and infrastructureRCF-0206UEBA/behavior analytics4 mapeosBehavioural baselines are consistently maintained and anomalous deviations are investigated
Técnica
RCF-0204Alerting & triage5 mapeosTechnical tools route alerts to the correct team, track response times and escalate unacknowledged alertsRCF-0198Centralized logging5 mapeosTechnical tools aggregate logs from all systems into a centralised platform for analysis and retentionRCF-0213Detection engineering4 mapeosTechnical tools support detection rule development, testing and deployment at scale across the monitoring platformRCF-0210Log protection & retention3 mapeosTechnical controls write logs to tamper-evident storage and enforce retention periods automaticallyRCF-0201SIEM use cases4 mapeosSIEM correlation rules automatically detect threat patterns and generate alerts for investigationRCF-0216Telemetry coverage5 mapeosTechnical tools map telemetry coverage across the environment and alert when expected sources stop sending dataRCF-0195Time sync4 mapeosTechnical controls enforce NTP synchronisation and alert when system clocks drift beyond acceptable thresholdsRCF-0207UEBA/behavior analytics4 mapeosUEBA tools automatically build user and entity behaviour profiles and alert on statistically significant deviations
Esta familia en ISO/IEC 27001:2022
Cada elemento de marco al que mapean los controles de la familia, primero los más conectados; agrupado por familia del Sekit CSF, nunca por el índice del propio marco.
Esta familia en NIST CSF 2.0
Esta familia en ISO/IEC 42001:2023 — Annex A
Pregúntale a Sekura: «¿Qué evidencia demuestra Logging & Monitoring?»
También vía MCP, gratis con cuenta