Skip to main content
MON

Continuous Monitoring

76 controls

Maintain situational awareness through centralized collection, correlation and analysis of security-relevant telemetry from Technology Assets, Applications and Services (TAAS).

SCF # Control Name Weight NIST CSF Frameworks
MON-01 Continuous Monitoring Policy 10 — Critical Govern 17
MON-02 Continuous Monitoring 10 — Critical Govern 132
MON-03 Event Log & Security-Relevant Telemetry Monitoring 10 — Critical Detect 95
MON-03.1 Centralized Management of Event Log & Security-Relevant Telemetry Content 5 — Medium Detect 13
MON-03.2 Analyze and Prioritize Monitoring Requirements 5 — Medium Detect 18
MON-03.3 Audit Level Adjustments 5 — Medium Detect 35
MON-04 System Generated Event Logs & Security-Relevant Telemetry 7 — High Detect 83
MON-04.1 System-Wide / Time-Correlated Audit Trail 5 — Medium Detect 32
MON-05 Centralized Collection of Event Logs & Security-Relevant Telemetry 10 — Critical Detect 88
MON-05.1 Centralized Event Log & Security-Relevant Telemetry Review & Analysis 5 — Medium Detect 42
MON-05.2 Event Log & Security-Relevant Telemetry Analysis & Triage 7 — High Detect 16
MON-05.3 Event Log & Security-Relevant Telemetry Review Escalation Matrix 7 — High Detect 7
MON-05.4 Automated Tools for Real-Time Event Log & Security-Relevant Telemetry Analysis 9 — Critical Detect 53
MON-05.5 Automated Incident Responder Alerting 5 — Medium Detect 21
MON-06 Monitoring Reporting 7 — High Detect 49
MON-06.1 Trend Analysis Reporting 5 — Medium Detect 12
MON-07 Alert Threshold Tuning 5 — Medium Detect 13
MON-08 Correlate Monitoring Information 9 — Critical Detect 60
MON-08.1 Integration of Scanning & Other Monitoring Information 5 — Medium Detect 25
MON-08.2 Correlation with Physical Monitoring 5 — Medium Detect 12
MON-09 Content of Event Logs 10 — Critical Detect 98
MON-09.1 Audit Trails 10 — Critical Detect 32
MON-10 Event Log & Security-Relevant Telemetry Storage Capacity 8 — High Detect 32
MON-10.1 Event Log & Security-Relevant Telemetry Storage Capacity Alerting 5 — Medium Detect 12
MON-11 Time Stamps 10 — Critical Detect 42
MON-11.1 Synchronization With Authoritative Time Source 8 — High Detect 40
MON-12 Protection of Event Logs & Security-Relevant Telemetry 10 — Critical Detect 74
MON-12.1 Event Log & Security-Relevant Telemetry Backup on Separate Physical Systems / Components 5 — Medium Detect 27
MON-12.2 Event Log & Security-Relevant Telemetry Access by Subset of Privileged Users 8 — High Detect 35
MON-12.3 Cryptographic Protection of Event Logs & Security-Relevant Telemetry 5 — Medium Protect 14
MON-12.4 Dual Authorization for Event Log & Security-Relevant Telemetry Movement 5 — Medium Protect 6
MON-12.5 Write Once Read Many (WORM) Event Log Generation 1 — Low Identify 2
MON-13 Event Log & Security-Relevant Telemetry Retention 10 — Critical Detect 78
MON-14 Privileged Functions Logging 8 — High Detect 35
MON-14.1 Account Creation and Modification Logging 7 — High Detect 5
MON-14.2 Privileged User Oversight 5 — Medium Detect 27
MON-15 Inventory of Technology Asset Event Logging 7 — High Identify 1
MON-16 Anomalous Behavior 10 — Critical Detect 68
MON-16.1 Unusual Transactions 7 — High Protect 6
MON-17 Monitoring for Indicators of Compromise (IOC) 5 — Medium Detect 38
MON-17.1 Deactivated Account Activity 9 — Critical Detect 2
MON-17.2 Automated Response to Suspicious Events 5 — Medium Detect 6
MON-17.3 Insider Threats 8 — High Detect 6
MON-17.4 Third-Party Threats 8 — High Detect 5
MON-18 Individuals Posing Greater Risk 5 — Medium Detect 9
MON-18.1 Session Audit 7 — High Detect 7
MON-18.2 Real-Time Session Monitoring 4 — Medium Detect 2
MON-19 Monitoring For Information Disclosure 8 — High Detect 20
MON-19.1 Monitoring for Third-Party Information Disclosure 8 — High Identify 5
MON-20 Covert Channel Analysis 3 — Low Detect 6
MON-20.1 Analyze Traffic for Covert Exfiltration 5 — Medium Detect 12
MON-21 Unauthorized Activities 8 — High Detect 13
MON-21.1 Unauthorized Network Services 5 — Medium Detect 10
MON-22 Inbound & Outbound Communications Traffic 9 — Critical Detect 50
MON-22.1 Proxy Logging 8 — High Detect 3
MON-23 Network Intrusion Detection & Prevention Systems (NIDS & NIPS) Monitoring 9 — Critical Detect 39
MON-24 Host Intrusion Detection & Prevention Systems (HIDS & HIPS) Monitoring 8 — High Detect 10
MON-25 De-Militarized Zone (DMZ) Monitoring 8 — High Protect 20
MON-26 Wireless Network Monitoring 5 — Medium Detect 19
MON-27 File Integrity Monitoring (FIM) 9 — Critical Detect 30
MON-28 File Activity Monitoring (FAM) 5 — Medium Detect 1
MON-29 Permitted Monitoring Actions 5 — Medium Protect 7
MON-29.1 Changes by Authorized Individuals 5 — Medium Detect 8
MON-29.2 Query Parameter Audits of Personal Data (PD) 3 — Low Detect 4
MON-30 Sensitive Event Log & Security-Relevant Telemetry Data 8 — High Detect 24
MON-30.1 Limit Personal Data (PD) In Event Logs & Security-Relevant Telemetry 8 — High Detect 6
MON-31 Verbosity Logging for Boundary Devices 5 — Medium Detect 2
MON-32 Database Logging 8 — High Detect 9
MON-33 Response To Event Log Processing Failures 8 — High Detect 39
MON-33.1 Real-Time Alerts of Event Logging Failure 6 — Medium Detect 13
MON-34 Non-Repudiation 8 — High Protect 15
MON-34.1 Identity Binding 4 — Medium Protect 6
MON-35 Alternate Event Logging Capability 3 — Low Detect 4
MON-36 Sharing of Event Logs & Security-Relevant Telemetry 5 — Medium Detect 9
MON-36.1 Cross-Organizational Monitoring 3 — Low Detect 8
MON-37 Control Assurance Automation (CAA) Data Feed Identification 6 — Medium Detect 0

The Secure Controls Framework (SCF) is maintained by SCF Council. Use of SCF content is subject to the SCF Terms & Conditions.

Manage SCF Controls in SCF Connect

Streamline your compliance program with automated control tracking, evidence management, and framework mapping.