Sekit CSF · Familia
Logging & Monitoring
24 controles en 8 temas, cada uno visto a través de las lentes de política, proceso y técnica.
Política
RCF-0202Alerting & triagesin mapeos aúnThe company formally defines how security alerts are prioritised, assigned and responded toRCF-0196Centralized loggingsin mapeos aúnThe company formally requires that security-relevant events from all systems are collected in a central locationRCF-0211Detection engineeringsin mapeos aúnThe company formally develops and maintains detection logic tailored to its own environment and threat profileRCF-0208Log protection & retentionsin mapeos aúnThe company formally defines how long logs must be retained and how they must be protected from tamperingRCF-0199SIEM use casessin mapeos aúnFormal detection scenarios are defined to identify known threats using collected log dataRCF-0214Telemetry coveragesin mapeos aúnThe company formally identifies which systems must generate security telemetry and ensures there are no blind spotsRCF-0193Time syncsin mapeos aúnThe company formally requires all systems to synchronise their clocks to a trusted time sourceRCF-0205UEBA/behavior analyticssin mapeos aúnThe company formally deploys behavioural analysis to identify anomalous activity that rules-based detection misses
Proceso
RCF-0203Alerting & triagesin mapeos aúnSecurity alerts are consistently triaged within defined timeframes and false positives are tuned outRCF-0197Centralized loggingsin mapeos aúnLog sources are consistently onboarded to the central logging platform and gaps are identified and closedRCF-0212Detection engineeringsin mapeos aúnDetection rules are consistently developed, tested and refined using threat intelligence and past incidentsRCF-0209Log protection & retentionsin mapeos aúnLog retention policies are consistently enforced and log integrity is verifiedRCF-0200SIEM use casessin mapeos aúnSIEM detection rules are consistently reviewed and updated to address emerging threatsRCF-0215Telemetry coveragesin mapeos aúnTelemetry coverage is consistently assessed and gaps in visibility are remediatedRCF-0194Time syncsin mapeos aúnTime synchronisation is consistently configured and verified across all systems and infrastructureRCF-0206UEBA/behavior analyticssin mapeos aúnBehavioural baselines are consistently maintained and anomalous deviations are investigated
Técnica
RCF-0204Alerting & triagesin mapeos aúnTechnical tools route alerts to the correct team, track response times and escalate unacknowledged alertsRCF-0198Centralized loggingsin mapeos aúnTechnical tools aggregate logs from all systems into a centralised platform for analysis and retentionRCF-0213Detection engineeringsin mapeos aúnTechnical tools support detection rule development, testing and deployment at scale across the monitoring platformRCF-0210Log protection & retentionsin mapeos aúnTechnical controls write logs to tamper-evident storage and enforce retention periods automaticallyRCF-0201SIEM use casessin mapeos aúnSIEM correlation rules automatically detect threat patterns and generate alerts for investigationRCF-0216Telemetry coveragesin mapeos aúnTechnical tools map telemetry coverage across the environment and alert when expected sources stop sending dataRCF-0195Time syncsin mapeos aúnTechnical controls enforce NTP synchronisation and alert when system clocks drift beyond acceptable thresholdsRCF-0207UEBA/behavior analyticssin mapeos aúnUEBA tools automatically build user and entity behaviour profiles and alert on statistically significant deviations
Pregúntale a Sekura: «¿Qué evidencia demuestra Logging & Monitoring?»
Conecta tu IA · MCP gratis
https://staging.sekit.ai/api/mcp/crosswalk- En Claude o ChatGPT, añade un conector personalizado y pega esta URL.
- Inicia sesión con tu correo para terminar. Gratis, de solo lectura, sin necesidad de organización.