OPS-03Secure Operations

Logging and monitoring

Security-relevant events are logged, retained and reviewed, with alerts that reach a person who acts.

Why it exists

Logs nobody reads are storage, not detection.

What usually proves it

Logging configuration, retention, alert handling records.

Smaller organizations

Cloud provider logs, one alert channel, reviewed weekly.

Mapped to

  • Fully addressedSOC 2 Trust Services Criteria · CC7.2
  • Fully addressedISO/IEC 27001 Annex A · A.8.15
  • Fully addressedNIST Cybersecurity Framework · DE.CM-01
  • Fully addressedPCI DSS · 10.2
  • Fully addressedHIPAA Security Rule · 164.312(b)
  • Partially addressedGDPR · Art. 32 — Implied by appropriate measures.
  • Fully addressedEU AI Act · Art. 12
  • Fully addressedNIST AI Risk Management Framework · MEASURE 3.1