Back to catalog
MON-05MONContinuous Monitoring
Response To Event Log Processing Failures
Description
Mechanisms exist to alert appropriate personnel in the event of a log processing failure and take actions to remedy the disruption.
Cross-Mappings
252 paths across 4 frameworks
Cross-Mappings
NIST 800-531 mapping
AU-5
1.00
- Secure Controls Framework · 2026.2 · scf_strm · equivalent
NIST 800-1711 mapping
3.3.4
1.00
- Secure Controls Framework · 2026.2 · scf_strm · equivalent
- NIST · Rev 2 (Feb 2020, errata Jan 2021) · nist_800_171_app_d · equivalent
CCI5 mappings
CCI-000139
1.00
- Secure Controls Framework · 2026.2 · scf_strm · equivalent
- DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-000140
1.00
- Secure Controls Framework · 2026.2 · scf_strm · equivalent
- DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-001490
1.00
- Secure Controls Framework · 2026.2 · scf_strm · equivalent
- DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-001572
1.00
- Secure Controls Framework · 2026.2 · scf_strm · equivalent
- DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-003814
1.00
- Secure Controls Framework · 2026.2 · scf_strm · equivalent
- DISA · 2025-01-23 · disa_cci_list · equivalent
STIG167 mappings
SV-102381r1_ruleThe SEL-2740S must alert the ISSO and SA (at a minimum) in the event of an audit processing failure.
1.00
- Secure Controls Framework · 2026.2 · scf_strm · equivalent
- DISA · 2025-01-23 · disa_cci_list · equivalent
- DISA · V1R1 · disa_xccdf · related
SV-203611r958424_ruleThe operating system must alert the ISSO and SA (at a minimum) in the event of an audit processing failure.
1.00
- Secure Controls Framework · 2026.2 · scf_strm · equivalent
- DISA · 2025-01-23 · disa_cci_list · equivalent
- DISA · 3 · disa_xccdf · related
SV-204652r960912_ruleAAA Services must be configured to alert the SA and ISSO when any audit processing failure occurs.
1.00
- Secure Controls Framework · 2026.2 · scf_strm · equivalent
- DISA · 2025-01-23 · disa_cci_list · equivalent
- DISA · V2R2 · disa_xccdf · related
SV-204728r960912_ruleThe application server must alert the SA and ISSO, at a minimum, in the event of a log processing failure.
1.00
- Secure Controls Framework · 2026.2 · scf_strm · equivalent
- DISA · 2025-01-23 · disa_cci_list · equivalent
- DISA · 4 · disa_xccdf · related
SV-204934r395937_ruleThe ALG must send an alert to, at a minimum, the ISSO and SCA when an audit processing failure occurs.
1.00
- Secure Controls Framework · 2026.2 · scf_strm · equivalent
- DISA · 2025-01-23 · disa_cci_list · equivalent
- DISA · 2 · disa_xccdf · related
SV-205471r960912_ruleThe Mainframe Product must alert the system administrator (SA) and information system security officer (ISSO) (at a minimum) in the event of an audit processing failure.
1.00
- Secure Controls Framework · 2026.2 · scf_strm · equivalent
- DISA · 2025-01-23 · disa_cci_list · equivalent
- DISA · 3 · disa_xccdf · related
SV-206366r960912_ruleThe web server must use a logging mechanism that is configured to alert the ISSO and SA in the event of a processing failure.
1.00
- Secure Controls Framework · 2026.2 · scf_strm · equivalent
- DISA · 2025-01-23 · disa_cci_list · equivalent
- DISA · 4 · disa_xccdf · related
SV-207358r958424_ruleThe VMM must alert the ISSO and SA (at a minimum) in the event of an audit processing failure.
1.00
- Secure Controls Framework · 2026.2 · scf_strm · equivalent
- DISA · 2025-01-23 · disa_cci_list · equivalent
- DISA · 2 · disa_xccdf · related
SV-207691r1038960_ruleIn the event of a logging failure caused by the lack of audit record storage capacity, the Palo Alto Networks security platform must continue generating and storing audit records if possible, overwriting the oldest audit records in a first-in-first-out manner.
1.00
- Secure Controls Framework · 2026.2 · scf_strm · equivalent
- DISA · 2025-01-23 · disa_cci_list · equivalent
- DISA · V3R2 · disa_xccdf · related
SV-213681r879571_ruleUnless it has been determined that availability is paramount, DB2 must, upon audit failure, cease all auditable activity.
1.00
- Secure Controls Framework · 2026.2 · scf_strm · equivalent
- DISA · 2025-01-23 · disa_cci_list · equivalent
- DISA · V2R1 · disa_xccdf · related
+157 more (top 10 by confidence shown)
Control mappings provided by the Secure Controls Framework (SCF).
SCF
Powered by the Secure Controls Framework
The control catalog, cross-mappings, and STRM relationship data shown here are provided by the Secure Controls Framework (SCF), 2026.2. Every mapping is credited to SCF as the methodology, with the SCF reference and version stored alongside it.
© SCF Council, LLC. Secure Controls Framework content is free and shown here with attribution. securecontrolsframework.com · About SCF on STIGViewer