Implementation examples
15 examples referencing SIEM
- SI.L2-3.14.7[a] [b]
Write down what authorized use looks like, then alert on what falls outside it
AO coverage. Addresses both Identify Unauthorized Use objectives: authorized use of the system is defined, and unauthorized use is identified. Defining authorized use [a]. This is the objective most…
ControlVerdict Corpus@cv-corpusJul 31, 2026No verdicts yet - SI.L2-3.14.6[a] [b] [c]
Inbound, outbound, and off-network telemetry with business-hours triage and on-call paging
AO coverage. Addresses all three Monitor Communications for Attacks objectives: the system is monitored, inbound traffic is monitored, and outbound traffic is monitored. System monitoring [a]. EDR…
ControlVerdict Corpus@cv-corpusJul 31, 2026No verdicts yet - SC.L2-3.13.13[a] [b]
Macro and script allow-listing, with execution telemetry landing in the SIEM
AO coverage. Addresses both Mobile Code objectives: use of mobile code is controlled, and use of mobile code is monitored. What counts as mobile code here. Office macros and add-ins, browser…
ControlVerdict Corpus@cv-corpusJul 31, 2026No verdicts yet - SC.L2-3.13.7[a]
Always-on full tunnel with local LAN access and NIC bridging disabled in client policy
AO coverage. Addresses the single Split Tunneling objective for managed endpoints that can reach CUI. Client posture. The VPN profile is deployed by MDM, set to always-on with user-logon connect, and…
ControlVerdict Corpus@cv-corpusJul 31, 2026No verdicts yet - CM.L2-3.4.3[a] [b] [c] [d]
Intended change versus actual change: reconciling tickets against what the tools logged
AO coverage. Addresses all four System Change Management objectives: changes are tracked [a], reviewed [b], approved or disapproved [c], and logged [d]. Tracking [a]. Every change to an in-scope…
ControlVerdict Corpus@cv-corpusJul 31, 2026No verdicts yet - AU.L2-3.3.9[a] [b]
Two named log administrators; analysts and engineers get read-only search
AO coverage. Addresses both Audit Management objectives: the subset of privileged users allowed to manage audit logging functionality is defined, and management is limited to that subset. Defined…
ControlVerdict Corpus@cv-corpusJul 31, 2026No verdicts yet - AU.L2-3.3.8[a] [b] [c] [d] [e] [f]
Write-once archive in a separate account so a log admin cannot erase their own trail
AO coverage. Addresses all six Audit Protection objectives: audit information protected from unauthorized access [a], modification [b], and deletion [c], and the logging tools themselves protected…
ControlVerdict Corpus@cv-corpusJul 31, 2026No verdicts yet - AU.L2-3.3.6[a] [b]
Saved searches and a scoped assessor report instead of multi-gigabyte CSV dumps
AO coverage. Addresses both Reduction & Reporting objectives: an audit record reduction capability supporting on-demand analysis, and a report generation capability supporting on-demand reporting.…
ControlVerdict Corpus@cv-corpusJul 31, 2026No verdicts yet - AU.L2-3.3.4[a] [b] [c]
Logging failures page the on-call instead of landing in an unread inbox
AO coverage. Addresses all three Audit Failure Alerting objectives: who is alerted, which failure types generate an alert, and that the alert actually reaches those people. Who is alerted [a].…
ControlVerdict Corpus@cv-corpusJul 31, 2026No verdicts yet - AU.L2-3.3.3[a] [b] [c]
Quarterly logged-event review that actually changes the catalog
AO coverage. Addresses all three Event Review objectives: a review process with defined timing, review of the logged event types against it, and updates resulting from that review. Defined process…
ControlVerdict Corpus@cv-corpusJul 31, 2026No verdicts yet - AU.L2-3.3.2[a] [b]
Retiring the shared itadmin account so every action names a human
AO coverage. Addresses both User Accountability objectives: the record content needed to trace actions to a user is defined, and created records actually contain it. Defined record content [a]. For…
ControlVerdict Corpus@cv-corpusJul 31, 2026No verdicts yet - AC.L2-3.1.11[a] [b]
Idle and max session lifetimes on VPN and SSO
AO coverage. Addresses both Session Termination objectives. VPN. Idle disconnect ≤12 hours; absolute session lifetime forces re-auth. Concurrent sessions limited to one unless ticketed. SSO. IdP…
ControlVerdict Corpus@cv-corpusJul 31, 2026No verdicts yet - AC.L2-3.1.8[a] [b]
Smart lockout on IdP and VPN; no endless password spray
AO coverage. Addresses both Unsuccessful Logon Attempts objectives. Thresholds. IdP smart lockout after repeated failures (org baseline: lock after sustained failures within a window, with…
ControlVerdict Corpus@cv-corpusJul 31, 2026No verdicts yet - AC.L2-3.1.7[a] [b] [c] [d]
Block privileged functions for standard users; log every elevation
AO coverage. Addresses all Privileged Functions objectives (prevent + capture). Prevent. Standard users cannot activate Global Admin, User Admin, or enclave storage admin roles. Those roles are…
ControlVerdict Corpus@cv-corpusJul 31, 2026No verdicts yet - AC.L2-3.1.12[a] [b] [c]
Compliant-device VPN or SSO only; session recording for privileged remote admin
AO coverage. Claims objectives [a], [b], and [c] (permit, identify types, and control remote access). Objective [d] (monitor sessions) is only partially covered here: VPN connect/disconnect and…
ControlVerdict Corpus@cv-corpusJul 31, 2026No verdicts yet