Physical access is monitored to identify potential cybersecurity events
Monitoring is done on physical access attempts, and any anomalies detected (such as unapproved access attempts) are tagged as requiring further review to determine whether they are indicators of cybersecurity events (rather than an error, for example).
Related Practices · Input From: Implementing ARCHITECTURE-3a provides input that may be useful for implementing this practice. · Progression: This practice is part of a practice progression. Practice progressions are groups of related practices that represent increasingly complete or more advanced implementations of an activity. The practices in this progression include: ACCESS-3c, ACCESS-3j.