Unusual or suspicious access to assets is not monitored by security monitoring solutions
Context and Guidance: Identities (users) are the means used to provision access to assets (such as networks, systems, and applications). It is important that security monitoring solutions, such as a SIEM (Security Information and Event Management) tool, are actively used to monitor identities (users) for suspicious or unusual activity.
This may include consideration of behavioural trends such as: