MON-16.4 ยท Account Creation and Modification Logging

Control Description

Automated mechanisms exist to generate event logs for permissions changes to privileged accounts and/or groups.

Control Question
Assessment question for control validation

Does the organization use automated mechanisms to generate event logs for permissions changes to privileged accounts and/or groups?

Control Weighting
7
Validation Cadence
Quarterly
NIST CSF Function
Detect
Supply Chain Risk Management (SCRM) Tiers
Applicable SCRM tier levels for this control
Tier 3 - Tactical
Core Control Designations
Special designations and baseline inclusions
MAD: MON-16.4
ESP Level 1: MON-16.4
ESP Level 2: MON-16.4
ESP Level 3: MON-16.4