SM-27—System Monitoring Legal Opinion
>Control Description
Organization obtains legal opinion with regard to monitoring activities in accordance with applicable requirements and mandates.
Theme
Process
Type
Preventive
Policy/Standard
Logging & Monitoring Standard>Implementation Guidance
1. Design a legal process to ensure that only approved monitoring criteria is established as per applicable legal, contractual, and government requirements. 2. Ensure any change in monitoring criteria takes legal sign off into consideration.
>Testing Procedure
1. Inspect organization's legal process to ensure approved monitoring criteria is established as per applicable legal, contractual, and government requirements. 2. Validate whether any change in monitoring criteria takes legal sign off into consideration.
>Audit Artifacts
E-SM-20
Ask AI
Configure your API key to use AI features.