Sekit CSF · Family
Logging & Monitoring
24 controls in 8 topics, each seen through the policy, process and technical lenses.
Policy
RCF-0202Alerting & triageno mappings yetThe company formally defines how security alerts are prioritised, assigned and responded toRCF-0196Centralized loggingno mappings yetThe company formally requires that security-relevant events from all systems are collected in a central locationRCF-0211Detection engineeringno mappings yetThe company formally develops and maintains detection logic tailored to its own environment and threat profileRCF-0208Log protection & retentionno mappings yetThe company formally defines how long logs must be retained and how they must be protected from tamperingRCF-0199SIEM use casesno mappings yetFormal detection scenarios are defined to identify known threats using collected log dataRCF-0214Telemetry coverageno mappings yetThe company formally identifies which systems must generate security telemetry and ensures there are no blind spotsRCF-0193Time syncno mappings yetThe company formally requires all systems to synchronise their clocks to a trusted time sourceRCF-0205UEBA/behavior analyticsno mappings yetThe company formally deploys behavioural analysis to identify anomalous activity that rules-based detection misses
Process
RCF-0203Alerting & triageno mappings yetSecurity alerts are consistently triaged within defined timeframes and false positives are tuned outRCF-0197Centralized loggingno mappings yetLog sources are consistently onboarded to the central logging platform and gaps are identified and closedRCF-0212Detection engineeringno mappings yetDetection rules are consistently developed, tested and refined using threat intelligence and past incidentsRCF-0209Log protection & retentionno mappings yetLog retention policies are consistently enforced and log integrity is verifiedRCF-0200SIEM use casesno mappings yetSIEM detection rules are consistently reviewed and updated to address emerging threatsRCF-0215Telemetry coverageno mappings yetTelemetry coverage is consistently assessed and gaps in visibility are remediatedRCF-0194Time syncno mappings yetTime synchronisation is consistently configured and verified across all systems and infrastructureRCF-0206UEBA/behavior analyticsno mappings yetBehavioural baselines are consistently maintained and anomalous deviations are investigated
Technical
RCF-0204Alerting & triageno mappings yetTechnical tools route alerts to the correct team, track response times and escalate unacknowledged alertsRCF-0198Centralized loggingno mappings yetTechnical tools aggregate logs from all systems into a centralised platform for analysis and retentionRCF-0213Detection engineeringno mappings yetTechnical tools support detection rule development, testing and deployment at scale across the monitoring platformRCF-0210Log protection & retentionno mappings yetTechnical controls write logs to tamper-evident storage and enforce retention periods automaticallyRCF-0201SIEM use casesno mappings yetSIEM correlation rules automatically detect threat patterns and generate alerts for investigationRCF-0216Telemetry coverageno mappings yetTechnical tools map telemetry coverage across the environment and alert when expected sources stop sending dataRCF-0195Time syncno mappings yetTechnical controls enforce NTP synchronisation and alert when system clocks drift beyond acceptable thresholdsRCF-0207UEBA/behavior analyticsno mappings yetUEBA tools automatically build user and entity behaviour profiles and alert on statistically significant deviations
Ask Sekura: “What evidence proves Logging & Monitoring?”
Connect your AI · free MCP
https://staging.sekit.ai/api/mcp/crosswalk- In Claude or ChatGPT, add a custom connector and paste this URL.
- Sign in with your email to finish. Free, read-only, no organization required.