- Severity
- HIGH
- Status
- OPEN
- Owner
- Information Security
- Root cause
- Monitoring & logging
- Test failure
- Design assessment (CDA)
- Opened
- 2026-01-15
- Due
- 2026-05-31
- Closed
- —
167 days old as of 2026-07-01OverdueRepeat
Critical log sources not forwarding to the MSSP; detection blind spots persist.
FAIL
tested 2026-03-31
This issue records a CDA failure, shown first.
Control Design Assessment (CDA)
Procedures evaluating whether the control is designed adequately.
- 1.Obtain and read the log source coverage procedure; confirm it defines the critical log source inventory and the quarterly verification cadence.DE.CM-09
- 2.Confirm the verification checks actual log ingestion at the MSSP, not just configuration intent.
Control Operating Effectiveness (COE)
Procedures evaluating whether the control operated over the testing period.
- 1.Select 25 critical log sources and confirm each was verified as forwarding to the MSSP within the quarter.
- 2.For sources found not forwarding, confirm the gap was remediated and re-verified.DE.CM-09
- 3.Confirm the verification was performed in every quarter of the period.
Related issues
Same root cause or a shared entity
Score contribution
Issue-pressure points as of 2026-07-01, before the factor is capped at 0–100.
- Managed Security Services Provider39 of 39 pts
100% of this entity’s issue pressure
Annual priority score: 46 · issue pressure carries 10% weight in the active model — one factor among several behind that score.
- HIGH severity: 25
- Overdue: +8
- Repeat finding: +6
Linked entities
- Managed Security Services Provider
VENDOR · HIGH