ISO 27001 A.8.16 — Monitoring activities
A.8.16 is about detection. Logging (A.8.15) records what happened; monitoring is the human or automated activity that notices it in time to matter.
A.8.16 is about detection. Logging (A.8.15) records what happened; monitoring is the human or automated activity that notices it in time to matter.
Networks, systems and applications shall be monitored for anomalous behaviour and appropriate actions taken to evaluate potential information security incidents. The standard expects defined monitoring scope, baselines for 'normal', and a response path when something looks abnormal.
Theme: Technological · New in ISO 27001:2022
It is the control that connects your tooling to your incident process. Auditors routinely ask: an alert fires at 2am — who sees it, and what do they do? If there is no answer, the control fails regardless of the tooling in place.
Most SMEs already own the capability inside Microsoft Defender, their identity provider and their cloud platform. The work is choosing which signals matter, tuning out the noise, and evidencing that a named person reviews them.
See the full list of all 93 Annex A controls or start from the Statement of Applicability template.
ISO-STANDARD.app ships all 93 Annex A controls pre-loaded, linked to your risks, evidence and owners — with an AI 'Fix this' plan for anything failing.
ISO-STANDARD.app ships a ready-to-adopt ISO 27001 workspace with the risk register, controls catalogue, policies and audit-ready exports already wired together — no spreadsheet sprawl, no consultant lock-in.
Prefer a conversation? Email hello@iso-standard.app — a real human responds within one business day.