Skip to main content

Security Monitoring & Detection

Description

Security Monitoring & Detection represents the capability responsible for collecting and analysing security events across the Scheol Lab infrastructure.

It allows the detection of suspicious behaviour, system anomalies and potential security incidents.


Asset Identification

AttributeValue
Asset IDBUS-MON-01
CI TypeBusiness
Asset NameSecurity Monitoring & Detection
Asset CategorySecurity Operations Capability
OwnerSecurity Role (Sec)
StatusPlanned
LocationInternal infrastructure
Primary FunctionDetection of malicious or abnormal activity

Asset Dependencies

Dependency TypeAssetStatus
PlatformLogging & SIEM HostsPlanned
Data SourceLog DataPlanned

Relationships

RelationshipTarget CI
UsesLogging & SIEM Hosts
UsesLog Data

Asset Classification

CriteriaLevel
Confidentiality🟨 Medium
Integrity🟥 High
Availability🟨 Medium

Criticality score: 🟥 High


Responsibilities

RoleResponsibility
Security Role (Sec)Monitoring rules and incident detection
Operations Role (Ops)Infrastructure hosting monitoring tools

Security Controls (High-Level)

  • Centralized log collection
  • Security event analysis
  • Monitoring dashboards
  • Alerting mechanisms

Security Considerations

The absence or failure of monitoring may delay detection of security incidents.

Controls focus on log integrity, monitoring coverage and alerting capabilities.

Methodological References:

  • ISO 27001 - Control 8.15 Logging ; Control 8.16 Monitoring activities.
  • NIST CSF - DE.CM Continuous Monitoring.
  • *EBIOS RM - Detection capabilities.