Anomalous logical access attempts are monitored as indicators of cybersecurity events
Monitoring is done on logical access attempts, and any anomalies detected (such as an attempted login with a user name that doesn’t exist within the system) are tagged as requiring further review to determine whether they are indicators of cybersecurity events (rather than user error, for example).
Related Practices · Input From: Implementing ARCHITECTURE-3a provides input that may be useful for implementing this practice.