Alarms and alerts are configured and maintained to support the identification of cybersecurity events
Monitoring requirements should include specifications for alarms and alerts to aid in the identification of cybersecurity events, such as thresholds, durations, and sources of activity. For example, an alarm might be configured to be triggered when connection requests exceed a specific number that is the established maximum for normal activity, thus indicating the possibility of a denial of service attack.