Back to catalog
MON-02.8MONContinuous Monitoring
Changes by Authorized Individuals
Description
Mechanisms exist to provide privileged users or roles the capability to change the auditing to be performed on specified system components, based on specific event criteria within specified time thresholds.
Cross-Mappings
23 paths across 3 frameworks
Cross-Mappings
NIST 800-531 mapping
AU-12(3)
1.00
- Secure Controls Framework · 2026.2 · scf_strm · equivalent
CCI6 mappings
CCI-001911
1.00
- Secure Controls Framework · 2026.2 · scf_strm · equivalent
- DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-001912
1.00
- Secure Controls Framework · 2026.2 · scf_strm · equivalent
- DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-001913
1.00
- Secure Controls Framework · 2026.2 · scf_strm · equivalent
- DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-001914
1.00
- Secure Controls Framework · 2026.2 · scf_strm · equivalent
- DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-002047
1.00
- Secure Controls Framework · 2026.2 · scf_strm · equivalent
- DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-003834
1.00
- Secure Controls Framework · 2026.2 · scf_strm · equivalent
- DISA · 2025-01-23 · disa_cci_list · equivalent
STIG9 mappings
SV-203699r971541_ruleThe operating system must provide the capability for assigned IMOs/ISSOs or designated SAs to change the auditing to be performed on all operating system components, based on all selectable event criteria in near real time.
1.00
- Secure Controls Framework · 2026.2 · scf_strm · equivalent
- DISA · 2025-01-23 · disa_cci_list · equivalent
- DISA · 3 · disa_xccdf · related
SV-207449r971541_ruleThe VMM must provide the capability for assigned IMOs/ISSOs or designated SAs to change the auditing to be performed on all VMM components, based on all selectable event criteria in near real time.
1.00
- Secure Controls Framework · 2026.2 · scf_strm · equivalent
- DISA · 2025-01-23 · disa_cci_list · equivalent
- DISA · 2 · disa_xccdf · related
SV-215252r971541_ruleAIX must provide the function for assigned ISSOs or designated SAs to change the auditing to be performed on all operating system components, based on all selectable event criteria in near real time.
1.00
- Secure Controls Framework · 2026.2 · scf_strm · equivalent
- DISA · 2025-01-23 · disa_cci_list · equivalent
- DISA · 3 · disa_xccdf · related
SV-233600r961863_rulePostgreSQL must provide the means for individuals in authorized roles to change the auditing to be performed on all application components, based on all selectable event criteria within organization-defined time thresholds.
1.00
- Secure Controls Framework · 2026.2 · scf_strm · equivalent
- DISA · 2025-01-23 · disa_cci_list · equivalent
- DISA · V3R1 · disa_xccdf · related
SV-241819r960891_ruleThe System Administrator (SA) and Information System Security Manager (ISSM) must configure the retention of the log records based on criticality level, event type, and/or retention period, at a minimum.
1.00
- Secure Controls Framework · 2026.2 · scf_strm · equivalent
- DISA · 2025-01-23 · disa_cci_list · equivalent
- DISA · 3 · disa_xccdf · related
SV-253308r971541_ruleThe system must be configured to audit Account Management - Security Group Management successes.
1.00
- Secure Controls Framework · 2026.2 · scf_strm · equivalent
- DISA · 2025-01-23 · disa_cci_list · equivalent
- DISA · 2 · disa_xccdf · related
SV-261410r996645_ruleSLEM 5 must have the auditing package installed.
1.00
- Secure Controls Framework · 2026.2 · scf_strm · equivalent
- DISA · 2025-01-23 · disa_cci_list · equivalent
- DISA · 1 · disa_xccdf · related
SV-263569r982425_ruleThe Central Log Server must implement the capability for organization-defined individuals or roles to change the auditing to be performed on organization-defined system components based on organization-defined selectable event criteria within organization-defined time thresholds.
1.00
- Secure Controls Framework · 2026.2 · scf_strm · equivalent
- DISA · 2025-01-23 · disa_cci_list · equivalent
- DISA · 3 · disa_xccdf · related
SV-79631r1_ruleThe DataPower Gateway must provide the capability for organization-identified individuals or roles to change the auditing to be performed based on all selectable event criteria within near-real-time.
1.00
- Secure Controls Framework · 2026.2 · scf_strm · equivalent
- DISA · 2025-01-23 · disa_cci_list · equivalent
- DISA · V1R2 · disa_xccdf · related
Control mappings provided by the Secure Controls Framework (SCF).
SCF
Powered by the Secure Controls Framework
The control catalog, cross-mappings, and STRM relationship data shown here are provided by the Secure Controls Framework (SCF), 2026.2. Every mapping is credited to SCF as the methodology, with the SCF reference and version stored alongside it.
© SCF Council, LLC. Secure Controls Framework content is free and shown here with attribution. securecontrolsframework.com · About SCF on STIGViewer