RACF-CC • Domain 6

Monitoring and Detection

Turn existing identity, endpoint, cloud and network telemetry into a focused review process that a small team can sustain and act upon.

Purpose

Logs become valuable when someone acts

Many organisations already generate useful alerts but lack a defined cadence, owner or triage route. RACF-CC begins with a small set of high-confidence signals aligned to realistic attack paths, then expands only when the team has capacity to review and respond.

What good looks like

Priority signals have owners and review frequencies, alerts are categorised consistently, evidence crosses platform boundaries when needed, and every significant alert reaches a recorded outcome or incident process.

Risk picture

Common visibility gaps

Fragmented telemetry

Identity, endpoint, cloud and firewall platforms each hold part of an attack story.

No review cadence

Important evidence can exist without being examined before its value expires.

Alert fatigue

Excess volume causes high-value events to be missed or reviewed too late.

Unowned alerts

Signals remain notifications rather than accountable security actions.

Internal blind spots

Perimeter visibility may not reveal lateral movement within trusted networks.

Missing escalation

A genuine event may not trigger containment, communication or evidence preservation.

Prioritised action

The RACF-CC monitoring control set

PriorityControl directionOutcomeEvidence
FirstDefine a lightweight monitoring checklist, cadence, owner and deputy.Makes review repeatable rather than ad hoc.Completed review log.
FirstReview risky sign-ins, repeated authentication failures and privileged activity.Shortens identity-compromise dwell time.Review and remediation records.
FirstReview high-severity endpoint alerts and repeated protection-rule events.Connects endpoint telemetry to containment.Alert outcomes and device actions.
FirstUse a severity and escalation checklist with expected actions.Turns detection into accountable response.Tickets and escalation timestamps.
NextReview access-policy impact and unmanaged-device patterns.Supports safe enforcement and reveals bypass routes.Policy-impact decisions.
NextMonitor unusual cloud downloads, sharing and sensitive-data activity.Improves detection of exfiltration and misuse.Investigated audit events.
NextReview perimeter attacks and targeted high-risk internal boundaries.Adds network context without collecting everything.Firewall or IDS review.
DevelopCentralise selected logs or use managed monitoring where justified.Improves correlation when operational capacity exists.Coverage, tuning and response service levels.

Implementation

A four-phase roadmap

Phase 1

Own the routine

  • Select actionable signals
  • Assign primary and backup reviewers
  • Create severity and triage rules
  • Record outcomes

Phase 2

Broaden context

  • Add cloud-data activity
  • Add firewall and gateway review
  • Correlate identity and endpoint events
  • Tune noisy detections

Phase 3

Cover high-risk gaps

  • Add selected internal boundaries
  • Monitor legacy exposure
  • Test alert-to-response paths
  • Track review sustainability

Phase 4

Scale deliberately

  • Centralise only useful sources
  • Consider external monitoring support
  • Improve correlation and automation
  • Retire detections with no value

Do not confuse collection with detection

Adding logs without review capacity can increase cost and cognitive load. Start with signals that have a clear owner and response action; measure false positives and time spent before expanding coverage.

Stage detections before expanding noise or automation

Audit/observe → pilot → validate → enable → monitor → review

New detections, log sources and automated actions should be tested with clear ownership, representative events and response capacity before broad enablement. Use the Safe Enforcement Pattern →

Evidence

Measure actionable visibility

Review completionScheduled monitoring reviews completed on time.
Triage timeTime from alert creation to ownership and initial decision.
Alert outcomesAlerts closed as benign, remediated or escalated with evidence.
Signal qualityActionable findings, false positives and repeated noise by source.
CoveragePriority identity, endpoint, data and boundary scenarios with a defined signal.
SustainabilityReviewer effort, backlog and missed review periods.

Residual risk and escalation

Record visibility and response gaps that remain

What may remain unresolved?

Fragmented portals, short log retention, missing legacy-system telemetry, manual review, incomplete correlation and lack of continuous or out-of-hours monitoring may remain.

Why might it remain?

Licensing, storage cost, platform limitations, integration effort, signal quality and limited reviewer capacity can constrain monitoring coverage.

Compensating safeguards

Prioritise high-value signals, increase preventative controls, protect critical logs, use scheduled reviews, define supplier escalation and retain manual investigation routes.

Risk owner

The owner of each monitored service owns the consequence of limited visibility, supported by monitoring and incident-response roles.

Review requirement

Review after incidents, missed reviews, alert backlog growth, service change, telemetry loss and at the agreed monitoring-assurance interval.

Escalation triggers

Confirmed compromise without useful telemetry, repeated monitoring gaps, unowned critical alerts, unsustainable backlog or loss of visibility over a critical service.

Recording does not equal acceptance. Monitoring gaps need a named consequence owner and an agreed decision on prevention, additional visibility or external support.

References

Standards alignment

Continue

Turn detection into coordinated action

Domain 7 defines the playbooks, decisions and communication needed when a security event becomes an incident.