MON-02
Centralized Collection of Security Event Logs
Description
Mechanisms exist to utilize a Security Incident Event Manager (SIEM), or similar automated tool, to support the centralized collection of security-related event logs.
Control Question
Does the organization utilize a Security Incident Event Manager (SIEM) or similar automated tool, to support the centralized collection of security-related event logs?
Control Metadata
Domain:
Continuous Monitoring
Validation Cadence:
Annual
Evidence Request List:
E-MON-01 E-MON-05
Framework Mappings
This control maps to the following compliance frameworks
MAS TRM
9.1.3
HKIA GL20
4.14.24.3
