MON-005 Security Monitoring and Alerting
Description
Production systems are monitored for anomalous behaviour, security events, and indicators of compromise. Alerts are generated for defined threat scenarios and reviewed by a responsible team within defined SLAs. Alert thresholds, suppression rules, and escalation paths are documented. A procedure covers a periodic review of the activity records themselves, naming the record sets in scope, among them the audit logs, the access reports and the incident tracking records, the interval for each and who performs it. Each review records what was examined, the period it covered and what it found, and a finding is carried into the incident process or into a recorded decision.
Rationale
Logs without active review provide no detection capability. Structured alerting with documented response paths transforms log data into a real-time security control. Alert triage reads what crossed a threshold; the record review reads the set, which is where the activity nobody wrote a rule for shows up. The two fail differently and the second is the one an organisation drops first, because nothing pages when it does not happen. The record sets are named because a review of the platform in general cannot be shown to have covered the access reports.
Applicability (9 profiles)
164.308(a)(1)(ii)(D) is now stated: a procedure for the periodic review of the activity records themselves, naming the record sets in scope, including the audit logs, the access reports and the incident tracking records, the interval for each and who performs it, with findings carried into the incident process or into a recorded decision. 164.312(b) stays split across MON-001 for the record limb and this control for the examine limb, which is why both hold a partial on it.
Framework Mappings (25)
| LOG-03 | Security Monitoring and Alerting | full |
| LOG-05 | Audit Logs Monitoring and Response | full |
| LOG-14 | Failures and Anomalies Reporting | full |
| LOG-15 | Input Monitoring | informative |
| LOG-16 | Output Monitoring | informative |
| LOG-03 | Security Monitoring and Alerting | full |
| LOG-05 | Audit Logs Monitoring and Response | full |
| LOG-14 | Failures and Anomalies Reporting | full |
| HIPAA-164.308.a.1.i | Security Management Process | informative |
| HIPAA-164.308.a.1.ii.D | Information System Activity Review | full |
| HIPAA-164.308.a.5.ii.C | Log-in Monitoring | informative |
| HIPAA-164.312.b | Audit Controls | partial |
| 8.16 | Monitoring activities | full |
| NIS2-CIR-3.2 | Monitoring and Logging | informative |
| NIS2-CIR-Art.7 | Significant Incidents for Cloud Computing Service Providers | informative |
| AC-2(12) | Account Management | Account Monitoring for Atypical Usage | full |
| AU-6 | Audit Record Review, Analysis, and Reporting | full |
| RA-10 | Threat Hunting | partial |
| SC-26 | Decoys | informative |
| SI-4 | System Monitoring | partial |
| SI-4(2) | System Monitoring | Automated Tools and Mechanisms for Real-time Analysis | partial |
| SI-4(4) | System Monitoring | Inbound and Outbound Communications Traffic | partial |
| SI-4(5) | System Monitoring | System-generated Alerts | full |
| ASI08 | Cascading Failures | informative |
| CC7.2 | Monitors System Components for Anomalous Behavior | full |
Evidence (3)
SIEM alert rule configuration showing defined detection rules for threat scenarios, with documented alert thresholds, suppression rules, and escalation paths.
Example: SIEM detection rule library export (e.g., Splunk saved searches, Elastic SIEM rules, Sentinel analytics rules) showing rule names, trigger conditions, severity assignments, and assigned response queues
Test: Export the SIEM detection rule configuration. Verify: (1) rules exist for core threat scenarios (brute force, privilege escalation, impossible travel, data exfiltration indicators, configuration change); (2) each rule has a defined severity, escalation path, and assigned response owner; (3) suppression and tuning rules are documented and reviewed; (4) the rule set was last reviewed within the defined interval.
Alert queue records showing security monitoring alerts were reviewed and actioned within defined SLAs.
Example: Ticketing system (Jira, PagerDuty, or equivalent) records of SIEM-generated alerts for the preceding 30 days, showing alert type, creation time, acknowledgement time, and resolution time
Test: Query the alert queue or incident ticketing system for SIEM-generated alerts in the last 30 days. Verify: (1) alerts were acknowledged within the defined SLA for each severity level; (2) each alert has a documented triage decision; (3) calculate the percentage of alerts meeting the response SLA and confirm it is at or above the defined threshold.
Records of the periodic review of the activity record sets, with the sets examined, the period covered, the reviewer and the findings.
Example: Information system activity review, Q2 2026, signed by the security operations lead on 7 July 2026.
Test: Verify: (1) the procedure names the record sets in scope, including the audit logs, the access reports and the incident tracking records, the interval for each and who performs the review, (2) a review record exists for every interval in the period, (3) each record names the sets examined and the period covered rather than asserting that a review took place, (4) findings are carried into the incident process or into a recorded decision, with neither left open past the period the procedure allows, (5) a set named in the procedure but not examined in the period carries a recorded reason.
Questions (3)
Are production systems monitored for anomalous behaviour and indicators of compromise?
Active monitoring requires both configured detection rules and a team responsible for reviewing and responding to alerts. Logs without active review provide no detection capability. Answer yes only where the periodic review of the record sets themselves also happens: alert triage reads what crossed a threshold, which is a different act from reading the audit logs, the access reports and the incident tracking records at a stated interval.
Which threat scenarios are covered by active detection rules in your SIEM or monitoring platform?
The first four categories are the minimum expected coverage. All seven indicate a mature detection programme.
What is the defined SLA for acknowledging and triaging high severity security monitoring alerts?
24/7 coverage with a 1-hour or faster acknowledgement SLA is the expectation for high severity alerts in a production environment.