What to Provide
(1) The documented policy/procedure that defines your organization's process for monitoring production infrastructure.
(2) A screenshot demonstrating the infrastructure monitoring dashboard or dashboards that you use to monitor all in-scope production resources.
(3) A screenshot of an example security event notification or example alert notification message created by your infrastructure monitoring tool.
Evidence Format
(1) Word/PDF document
(2) Screenshots or exported images in a common image file type, such as .jpg, .png, or .pdf.
(3) Screenshots or exported images in a common image file type, such as .jpg, .png, or .pdf.
Additional Guidance
For each tool that monitors your infrastructure, the evidence should demonstrate:
What is being monitored
What will trigger a notification
Who receives notification and how
Your infrastructure monitoring may be covered by multiple tools, or a single infrastructure monitoring tool (such as AWS CloudWatch, Azure Monitor, or Google Cloud Monitoring).
Associated Unified Control ID | Associated Framework Control |
CTRL-833 | LCL-49 |