A.8.16 Monitoring Activities
Control Objective
Networks, systems and applications shall be monitored for anomalous behaviour and appropriate actions taken to evaluate potential information security incidents.
Policy Statement
anDREa implements continuous, multi-layered monitoring architectures across its research infrastructure (myDRE), public cloud hosts, and corporate collaboration suites. By pairing automated real-time alerting with formalized incident escalation pathways, anDREa ensures that behavioral anomalies, authentication threats, and performance degradations are instantly flagged, evaluated, and mitigated.
1. Cloud & Platform Telemetry (myDRE / Microsoft Azure)
To protect the availability, integrity, and security of the myDRE ecosystem, anDREa maintains an internal, 24x7 monitoring and alerting solution built natively on top of Microsoft Azure telemetry tools. This framework aggregates real-time analytics and routes automated emergency alerts based on specific risk thresholds:
-
Identity & Access Anomalies: Immediate triggers are generated for high-risk authentication patterns, including:
- Repetitive or brute-force failed password attempts.
-
Failed MFA attempts (indicative of push-fatigue or credential stuffing attacks).
-
Privileged Configuration Changes: Real-time visibility into baseline structural changes, including:
- Any manual configuration changes to Administrator accounts.
- Automated alerts upon the activation of PIM roles (ensuring clear visibility of administrative lifecycle windows).
-
Infrastructure Telemetry: Automated resource performance alerts configured to catch operational drift, network spikes, processing bottlenecks, or potential Denial of Service (DoS) vectors.
2. Corporate Collaboration Space (Google Workspace)
Corporate environments are supervised using native, automated heuristic modeling engines:
- Monitoring activities within our business domains leverage the unified data streaming capabilities detailed under A.08.15 - Logging.
- Global administrators utilize the built-in alerting rules of the Google Workspace Security to flag suspicious document exfiltration, unauthorized administrative overrides, or abnormal external file distribution.
3. Incident Triaging and Response Escalation
Monitoring systems do not operate in isolation; they are tied directly to our incident management frameworks:
[Continuous Monitoring] ➔ [Anomaly Detected] ➔ [A.6.8 Event Reporting] ➔ [A.5.26 Incident Response]
- Identification: Automated telemetry engines or administrative audits uncover a technical anomaly or security deviation.
- Reporting & Intake: The finding is instantly logged as an observed or suspected event through the appropriate internal channels according to A.06.08 - Information security event reporting.
- Mitigation: If the anomaly is validated as a legitimate threat, the incident response team executes containment, eradication, and forensic recovery protocols in strict alignment with A.05.26 - Response to information security incidents.