ISO 27001 A.8.16 — Monitoring activities

A.8.16 is about detection. Logging (A.8.15) records what happened; monitoring is the human or automated activity that notices it in time to matter.

Michael McCarroll 6 min read Updated August 2026

What the control says

Networks, systems and applications shall be monitored for anomalous behaviour and appropriate actions taken to evaluate potential information security incidents. The standard expects defined monitoring scope, baselines for 'normal', and a response path when something looks abnormal.

Theme: Technological · New in ISO 27001:2022

Why it matters

It is the control that connects your tooling to your incident process. Auditors routinely ask: an alert fires at 2am — who sees it, and what do they do? If there is no answer, the control fails regardless of the tooling in place.

Most SMEs already own the capability inside Microsoft Defender, their identity provider and their cloud platform. The work is choosing which signals matter, tuning out the noise, and evidencing that a named person reviews them.

How to implement it

  1. Define monitoring scope from your risk assessment: identity (impossible travel, MFA failures, new admin roles), endpoints, email, internet-facing services and critical applications.
  2. Decide what 'normal' looks like so anomalies are meaningful, and set alert thresholds accordingly.
  3. Route alerts to a named owner or on-call rota with a documented triage path into the incident process (A.5.24 to A.5.26).
  4. Tune aggressively in the first month — an alert channel nobody reads is worse evidence than no channel at all.
  5. Keep a record of alerts triaged, including the ones dismissed as false positives and why.
  6. Review monitoring coverage and effectiveness periodically, and report it into management review.

Evidence auditors ask for

  • Documented monitoring scope and alert thresholds
  • Alert or incident queue showing triage with dates and outcomes
  • On-call or ownership arrangements, including out-of-hours cover
  • Examples of alerts escalated into the incident process
  • Tuning history and periodic effectiveness review

Common findings

  • Alerts generated to a shared mailbox nobody monitors.
  • No out-of-hours arrangement for a service the organisation calls critical.
  • Monitoring covers servers but not identity — the attack path most SMEs actually face.
  • No record of triage decisions, so the organisation cannot show alerts were assessed.

Related controls

  • A.8.15 Logging
  • A.8.17 Clock synchronisation
  • A.5.24 Information security incident management planning and preparation
  • A.5.25 Assessment and decision on information security events
  • A.5.7 Threat intelligence

See the full list of all 93 Annex A controls or start from the Statement of Applicability template.

FAQ

Does A.8.16 require a SIEM?
No. A SIEM is one way to satisfy it. Native tooling such as Microsoft Defender and Entra ID Protection, reviewed by a named owner with a documented triage path, is accepted for SMEs.
What is the difference between A.8.15 and A.8.16?
A.8.15 logging is about producing and protecting the records. A.8.16 monitoring is about actively watching for anomalies and acting on them. You need both; auditors test the link between them.
Do we need 24/7 monitoring?
Only if your risk assessment says so. What you must not do is claim 24/7 coverage in your documentation and then be unable to evidence it. Match the claim to reality, or buy managed cover.

Evidence A.8.16 without the spreadsheet

ISO-STANDARD.app ships all 93 Annex A controls pre-loaded, linked to your risks, evidence and owners — with an AI 'Fix this' plan for anything failing.

ISO-STANDARD.app ships a ready-to-adopt ISO 27001 workspace with the risk register, controls catalogue, policies and audit-ready exports already wired together — no spreadsheet sprawl, no consultant lock-in.

Free downloads for this topic

Prefer a conversation? Email hello@iso-standard.app — a real human responds within one business day.

Related guides
Trust & security
ISO 27001 aligned
Controls mapped to Annex A
Encryption in transit & at rest
TLS 1.3 · AES-256
MFA enforced
TOTP required for all admins
GDPR & UK GDPR
DPA on request · EU/UK data
SOC 2 ready posture
Audit-grade logging
RLS-isolated tenants
Row-level data separation
← All guidesHome →