Skip to main content
MuonPartners
Services
Architecture

Solution design and technology roadmapping

Solution AssessmentTechnology RoadmapsIntegration DesignSolution ArchitectureTechnical Design
Cyber Security

Security assessments, IAM, and compliance

AssessmentsIAMComplianceSecurity BaselineCyber Innovation
Network and Platform

Network architecture and cloud platforms

Network DesignCloud StrategyModernisation
Enterprise Architecture

Business-technology alignment

Business AlignmentPortfolio AnalysisGovernance
View all services
ProjectsCase StudiesInsightsToolsAbout
Contact Us

Services

Architecture
Solution AssessmentTechnology RoadmapsIntegration DesignSolution ArchitectureTechnical Design
Cyber Security
AssessmentsIAMComplianceSecurity BaselineCyber Innovation
Network and Platform
Network DesignCloud StrategyModernisation
Enterprise Architecture
Business AlignmentPortfolio AnalysisGovernance
ProjectsCase StudiesInsightsToolsAboutContact
Get in Touch
MuonPartners

Strategic technology consulting for Australian organisations navigating complexity.

Services

  • Architecture
  • Cyber Security
  • Network and Platform
  • Enterprise Architecture

Company

  • About
  • Products
  • Frameworks
  • Cross-Framework Mapping
  • Projects
  • Case Studies
  • Insights
  • Contact

Contact

  • [email protected]
  • Australia
  • LinkedIn

© 2026 Muon Partners. All rights reserved.

ABN 50 669 022 315 · A Muon Group company.

Privacy PolicyTerms of Service
  1. Frameworks
  2. >AESCSF
  3. >SITUATION
  4. >Perform Monitoring
  5. >AESCSF-SITUATION-2a
AESCSF-SITUATION-2aActive

Periodic reviews of log data or other cybersecurity monitoring activities are performed, at least in an ad hoc manner

Statement

Periodic reviews of log data or other cybersecurity monitoring activities are performed, at least in an ad hoc manner

Context and Guidance: Regular review and audit of event logs (manually or by automated tools) is a critical monitoring activity that is essential for situational awareness (e.g., through the detection of cybersecurity events or weaknesses). For example, logs may provide data about changes in the user environment that can result in necessary changes in access privileges or trigger alerts when systems important to the delivery of the function are unavailable. Another example of this is unintentionally powered off, deleted, or "resource exhausted" virtualised assets that may trigger alerts to ensure administrators are aware of system updates or patches that may not have been applied to these systems while they were offline or unable to respond.

Related Practices • Progression: This practice is part of a practice progression. Practice progressions are groups of related practices that represent increasingly complete or more advanced implementations of an activity. The practices in this progression include: SITUATION-2a, SITUATION-2b, SITUATION-2c, SITUATION-2f, SITUATION-2g.

Location

Domain
SITUATION
Objective
Perform Monitoring

Practice Details

Identifier
AESCSF-SITUATION-2a
Type
Practice
Domain
SITUATION
Objective
Perform Monitoring

Maturity Level

MIL-1MIL-2MIL-3

Security Profile

SP-1SP-2SP-3
ISM
ISM-0109relatedvia aescsf-reference
ISM-1228relatedvia aescsf-reference
C2M2
C2M2-SITUATION-2Aequivalentvia derived-shared-practice-structure
ISO 27001
ISO27001-7.1relatedvia aescsf-reference
ISO27001-7.2relatedvia aescsf-reference
View in graphReport an issue
← Back to Perform Monitoring
Perform Monitoring9 controls
AESCSF-SITUATION-2aPeriodic reviews of log data or other cybersecurity monitoring activities are performed, at least in an ad hoc mannerAESCSF-SITUATION-2bData and alerts from network and host monitoring infrastructure assets are periodically reviewed, at least in an ad h...AESCSF-SITUATION-2cMonitoring and analysis requirements are established and maintained for the function and address timely review of eve...AESCSF-SITUATION-2dIndicators of anomalous activity are established and maintained based on system logs, data flows, network baselines, ...AESCSF-SITUATION-2eAlarms and alerts are configured and maintained to support the identification of cybersecurity eventsAESCSF-SITUATION-2fMonitoring activities are aligned with the threat profile (THREAT-2e)AESCSF-SITUATION-2gMore rigorous monitoring is performed for higher priority assetsAESCSF-SITUATION-2hRisk analysis information (RISK-3d) is used to identify indicators of anomalous activityAESCSF-SITUATION-2iIndicators of anomalous activity are evaluated and updated periodically and according to defined triggers, such as sy...