Evidence from Security Logging Dashboard
Provide screenshots of the security log management dashboard or dashboards used to monitor all in-scope production systems for security related events.
For each tool that monitors events, the evidence should demonstrate:
What security events are being monitored
Security Event Alert Configurations or Example Alert
Provide screenshots of an example security event notification or alert message created by your security log management tools.
For each tool that monitors events, the evidence should demonstrate:
Which events will trigger a notification
Who receives a notification and how
Additional Guidance
Your log management may be covered by multiple tools, or a single log management tool (such as AWS CloudTrail, AWS GuardDuty, Azure Defender, or Google Security Command Center) may monitor several production systems by itself.
Example Evidence
AWS GuardDuty (Dashboard)
AWS GuardDuty (Alert Notification Configurations)
Google Security Command Center (Dashboard)
Google Security Command Center (Alert Notification Configurations)
Azure Defender (Dashboard)
Azure Defender (Alert Notification Configurations)
Associated Unified Control ID | Associated Framework Control |
CTRL-833 | LCL-48 |