ctl-036
Critical log sources feeding the MSSP are verified quarterly.
- Type
- DETECTIVE
- Automation
- SEMI_AUTOMATED
- Frequency
- QUARTERLY
- Owner
- Information Security
Control Design Assessment (CDA)
Procedures evaluating whether the control is designed adequately.
- 1.Obtain and read the log source coverage procedure; confirm it defines the critical log source inventory and the quarterly verification cadence.DE.CM-09
- 2.Confirm the verification checks actual log ingestion at the MSSP, not just configuration intent.
Control Operating Effectiveness (COE)
Procedures evaluating whether the control operated over the testing period.
- 1.Select 25 critical log sources and confirm each was verified as forwarding to the MSSP within the quarter.
- 2.For sources found not forwarding, confirm the gap was remediated and re-verified.DE.CM-09
- 3.Confirm the verification was performed in every quarter of the period.
Linked risks
- MSSP detection blind spotsmitigation 3
Framework mappings & latest test
LOG-07LOG-03
Latest test:FAIL2026-03-31