GASP AICF

Search controls and profiles

Search by control ID, name, domain or profile

MON-005 Security Monitoring and Alerting

Tier 2+ProviderDeployerGPAI Model ProviderManaged Service Provider

Description

Production systems are monitored for anomalous behaviour, security events, and indicators of compromise. Alerts are generated for defined threat scenarios and reviewed by a responsible team within defined SLAs. Alert thresholds, suppression rules, and escalation paths are documented. A procedure covers a periodic review of the activity records themselves, naming the record sets in scope, among them the audit logs, the access reports and the incident tracking records, the interval for each and who performs it. Each review records what was examined, the period it covered and what it found, and a finding is carried into the incident process or into a recorded decision.

Rationale

Logs without active review provide no detection capability. Structured alerting with documented response paths transforms log data into a real-time security control. Alert triage reads what crossed a threshold; the record review reads the set, which is where the activity nobody wrote a rule for shows up. The two fail differently and the second is the one an organisation drops first, because nothing pages when it does not happen. The record sets are named because a review of the platform in general cannot be shown to have covered the access reports.

Applicability (9 profiles)

SaaS AI Providerstablerequiredcore
Enterprise AI Deployerstablerequiredcore
GPAI Model Providerstablerequiredcore
High-Risk Provider (EU)stablerequiredcore
Public Body Deployer (EU)stablerequiredcore
DORA ICT Provider (EU)stablerequiredcore
HIPAA Business Associate (US)stablerequiredrole duty

164.308(a)(1)(ii)(D) is now stated: a procedure for the periodic review of the activity records themselves, naming the record sets in scope, including the audit logs, the access reports and the incident tracking records, the interval for each and who performs it, with findings carried into the incident process or into a recorded decision. 164.312(b) stays split across MON-001 for the record limb and this control for the examine limb, which is why both hold a partial on it.

NIS2 Cloud Provider (EU)stablerequiredcore

Framework Mappings (25)

LOG-03Security Monitoring and Alertingfull
LOG-05Audit Logs Monitoring and Responsefull
LOG-14Failures and Anomalies Reportingfull
LOG-15Input Monitoringinformative
LOG-16Output Monitoringinformative
LOG-03Security Monitoring and Alertingfull
LOG-05Audit Logs Monitoring and Responsefull
LOG-14Failures and Anomalies Reportingfull
HIPAA-164.308.a.1.iSecurity Management Processinformative
HIPAA-164.308.a.1.ii.DInformation System Activity Reviewfull
HIPAA-164.308.a.5.ii.CLog-in Monitoringinformative
HIPAA-164.312.bAudit Controlspartial
8.16Monitoring activitiesfull
NIS2-CIR-3.2Monitoring and Logginginformative
NIS2-CIR-Art.7Significant Incidents for Cloud Computing Service Providersinformative
AC-2(12)Account Management | Account Monitoring for Atypical Usagefull
AU-6Audit Record Review, Analysis, and Reportingfull
RA-10Threat Huntingpartial
SC-26Decoysinformative
SI-4System Monitoringpartial
SI-4(2)System Monitoring | Automated Tools and Mechanisms for Real-time Analysispartial
SI-4(4)System Monitoring | Inbound and Outbound Communications Trafficpartial
SI-4(5)System Monitoring | System-generated Alertsfull
ASI08Cascading Failuresinformative
CC7.2Monitors System Components for Anomalous Behaviorfull

Evidence (3)

configurationtechnicalautomated

SIEM alert rule configuration showing defined detection rules for threat scenarios, with documented alert thresholds, suppression rules, and escalation paths.

Example: SIEM detection rule library export (e.g., Splunk saved searches, Elastic SIEM rules, Sentinel analytics rules) showing rule names, trigger conditions, severity assignments, and assigned response queues

Test: Export the SIEM detection rule configuration. Verify: (1) rules exist for core threat scenarios (brute force, privilege escalation, impossible travel, data exfiltration indicators, configuration change); (2) each rule has a defined severity, escalation path, and assigned response owner; (3) suppression and tuning rules are documented and reviewed; (4) the rule set was last reviewed within the defined interval.

logtechnicalautomated

Alert queue records showing security monitoring alerts were reviewed and actioned within defined SLAs.

Example: Ticketing system (Jira, PagerDuty, or equivalent) records of SIEM-generated alerts for the preceding 30 days, showing alert type, creation time, acknowledgement time, and resolution time

Test: Query the alert queue or incident ticketing system for SIEM-generated alerts in the last 30 days. Verify: (1) alerts were acknowledged within the defined SLA for each severity level; (2) each alert has a documented triage decision; (3) calculate the percentage of alerts meeting the response SLA and confirm it is at or above the defined threshold.

recorddocumentmanual

Records of the periodic review of the activity record sets, with the sets examined, the period covered, the reviewer and the findings.

Example: Information system activity review, Q2 2026, signed by the security operations lead on 7 July 2026.

Test: Verify: (1) the procedure names the record sets in scope, including the audit logs, the access reports and the incident tracking records, the interval for each and who performs the review, (2) a review record exists for every interval in the period, (3) each record names the sets examined and the period covered rather than asserting that a review took place, (4) findings are carried into the incident process or into a recorded decision, with neither left open past the period the procedure allows, (5) a set named in the procedure but not examined in the period carries a recorded reason.

Questions (3)

boolean

Are production systems monitored for anomalous behaviour and indicators of compromise?

Active monitoring requires both configured detection rules and a team responsible for reviewing and responding to alerts. Logs without active review provide no detection capability. Answer yes only where the periodic review of the record sets themselves also happens: alert triage reads what crossed a threshold, which is a different act from reading the audit logs, the access reports and the incident tracking records at a stated interval.

multi

Which threat scenarios are covered by active detection rules in your SIEM or monitoring platform?

Brute force and credential stuffing attacksPrivilege escalation or unusual privilege useImpossible travel or authentication from anomalous locationsIndicators of data exfiltration (e.g. large data exports, unusual API query volumes)Configuration changes to security controlsMalware or suspicious process execution on endpointsLateral movement indicatorsNone of the above

The first four categories are the minimum expected coverage. All seven indicate a mature detection programme.

select

What is the defined SLA for acknowledging and triaging high severity security monitoring alerts?

Within 15 minutes (24/7 on-call coverage)Within 1 hour (24/7 on-call coverage)Within 4 hours (business hours coverage)Within 24 hoursNo defined SLA for alert triage

24/7 coverage with a 1-hour or faster acknowledgement SLA is the expectation for high severity alerts in a production environment.