Control detail

MSSP log source coverage review

ctl-036 · DETECTIVE · QUARTERLY

ctl-036

Critical log sources feeding the MSSP are verified quarterly.

Key control
Type
DETECTIVE
Automation
SEMI_AUTOMATED
Frequency
QUARTERLY
Owner
Information Security

Control Design Assessment (CDA)

Procedures evaluating whether the control is designed adequately.

  1. 1.Obtain and read the log source coverage procedure; confirm it defines the critical log source inventory and the quarterly verification cadence.DE.CM-09
  2. 2.Confirm the verification checks actual log ingestion at the MSSP, not just configuration intent.

Control Operating Effectiveness (COE)

Procedures evaluating whether the control operated over the testing period.

  1. 1.Select 25 critical log sources and confirm each was verified as forwarding to the MSSP within the quarter.
  2. 2.For sources found not forwarding, confirm the gap was remediated and re-verified.DE.CM-09
  3. 3.Confirm the verification was performed in every quarter of the period.

Linked risks

  • MSSP detection blind spotsmitigation 3

Framework mappings & latest test

LOG-07LOG-03
Latest test:FAIL2026-03-31