A.8.16 A.8 · Technological Controls New in 2022

A.8.16 — Monitoring activities

Monitor networks, systems and applications for anomalous behaviour and take appropriate actions to evaluate potential IS incidents.

Also written as A8.16, Annex A 8.16, ISO 27001:2022 A.8.16, ISO27001 A.8.16.

What ISO 27001 A.8.16 requires

Monitoring activities is one of 34 Technological Controls in ISO/IEC 27001:2022 Annex A. Monitor networks, systems and applications for anomalous behaviour and take appropriate actions to evaluate potential IS incidents. Technological controls are tested against system state, not policy text: expect the auditor to ask for configuration exports, tickets, or console screenshots showing the control is enforced in the live environment.

Audit evidence assessors look for

When preparing your Statement of Applicability (SoA) for A.8.16, gather artefacts such as:

  • Security monitoring policy and runbooks
  • SIEM alerting rules and threshold configuration
  • SOC monitoring schedule and analyst shift records
  • Sample alert triage and investigation records

How to implement A.8.16

  1. Decide what "anomalous" means before buying toolingMonitoring without a baseline generates volume, not signal. Define the behaviours that matter for your environment — impossible travel, privilege escalation, mass download, new admin account — and build detection for those. A SIEM ingesting everything and alerting on nothing is a common and expensive failure.
  2. Document coverage explicitlyRecord which systems send logs, which do not, and why. Coverage gaps are acceptable if they are known and risk-assessed; they are a finding when they are discovered by the auditor rather than declared by you.
  3. Define who looks and whenThe control requires taking appropriate actions, which presumes a human or automation with responsibility. Whether that is a 24/7 SOC, an MSSP, or one analyst reviewing each morning, write down the schedule and keep the shift or review records.
  4. Keep triage evidence across the whole periodAuditors sample alerts from across the audit window, not the last month. Keep the investigation record — what fired, who looked, what they concluded, what happened next — including the false positives, which demonstrate the process running.
  5. Tune and record the tuningAlert rules that are never adjusted signal that nobody is using them. A change history on detection rules is quiet but strong evidence that monitoring is operating rather than installed.

Common audit findings for A.8.16

What actually gets raised against A.8.16, in rough order of how often it comes up:

Scoping A.8.16

A.8.16 is new in ISO 27001:2022. Small organisations sometimes argue that formal monitoring is disproportionate — the control still applies, but the expected implementation scales. Cloud-native provider alerting reviewed on a defined cadence can be a legitimate implementation for a small team, provided the review is evidenced.

How A.8.16 maps to SOC 2 and NIST CSF

If you run more than one framework, the same evidence usually satisfies all of them. A.8.16 aligns with:

SOC 2: CC7.2 Anomaly and security event monitoring

NIST CSF 2.0: DE.CM-01 Network monitoring, DE.CM-03 Personnel activity and technology usage monitoring, DE.CM-06 External provider activity monitoring, DE.CM-09 Computing hardware, software and services monitoring

ISO 27001:2013 mapping

A.8.16 is a new control introduced in the 2022 revision with no direct 2013 equivalent. Treat it as a fresh requirement when transitioning from ISO 27001:2013.

Map A.8.16 to NIST CSF & SOC 2 →
Crosswalk this control in the Control Mapper & Gap Assessment.
Document the risk →
Record treatment for gaps against A.8.16 in the Risk Register.

Related Annex A controls

A.7.4 Physical security monitoring A.8.15 Logging A.8.17 Clock synchronisation A.8.20 Networks security A.5.22 Monitoring, review and change management of supplier services A.8.1 User end point devices

See all 34 Technological Controls →

Frequently asked questions

Is ISO 27001 A.8.16 mandatory?

Annex A controls are not mandatory in the abstract. Clause 6.1.3 requires you to compare your risk treatment plan against Annex A and justify, in the Statement of Applicability, any control you exclude. If your risk assessment surfaces a risk that A.8.16 addresses, excluding it needs a documented, risk-based rationale that an auditor will test.

How do auditors test ISO 27001 A.8.16?

In two passes. First design: does a documented control exist, is it owned, and does it address the risk? Then operating effectiveness: the auditor samples records from across the audit period to confirm the control actually ran. A Stage 2 audit will typically pull several samples, so evidence that only exists for the month before the audit is a common finding.

How often should A.8.16 be reviewed?

ISO 27001 sets no fixed interval — it requires review at "planned intervals" and after significant change. Annual review is the norm most certification bodies expect, with an out-of-cycle review triggered by incidents, major system changes, restructures, or new regulatory obligations. Record the review date and outcome either way; an undated control is treated as unreviewed.

What does ISO 27001 A.8.16 map to in SOC 2 and NIST CSF?

A.8.16 aligns with SOC 2 CC7.2 and NIST CSF DE.CM-01, DE.CM-03, DE.CM-06, DE.CM-09. Evidence gathered for one framework will usually satisfy the others, which is the basis for a test-once, satisfy-many control library.

Is A.8.16 a new control in ISO 27001:2022?

Yes. A.8.16 is one of the 11 controls introduced in the 2022 revision and has no direct ISO 27001:2013 equivalent, so a transitioning ISMS has no prior evidence to re-point and should treat it as a fresh implementation.

What are the most common audit findings for A.8.16?

Alerts generated but no evidence anyone triaged them, particularly in the earlier months of the audit period. Log coverage that omits significant systems, discovered during the audit rather than declared.