OPS-03Secure Operations
Logging and monitoring
Security-relevant events are logged, retained and reviewed, with alerts that reach a person who acts.
Why it exists
Logs nobody reads are storage, not detection.
What usually proves it
Logging configuration, retention, alert handling records.
Smaller organizations
Cloud provider logs, one alert channel, reviewed weekly.
Mapped to
- Fully addressedSOC 2 Trust Services Criteria · CC7.2
- Fully addressedISO/IEC 27001 Annex A · A.8.15
- Fully addressedNIST Cybersecurity Framework · DE.CM-01
- Fully addressedPCI DSS · 10.2
- Fully addressedHIPAA Security Rule · 164.312(b)
- Partially addressedGDPR · Art. 32 — Implied by appropriate measures.
- Fully addressedEU AI Act · Art. 12
- Fully addressedNIST AI Risk Management Framework · MEASURE 3.1