# SP-025 Advanced Monitoring and Detection

Status: published. Release 26.02. Modified 2026-02-06. Licence: CC BY-SA 4.0.

Scope: Security architecture for building advanced detection and response capabilities against sophisticated threats. Covers SIEM deployment, security operations centre design, continuous monitoring, threat intelligence integration, behavioural analytics, and incident response orchestration for detecting adversaries who have bypassed preventive controls.
Use when: Apply this pattern if your organisation may be a likely target of sophisticated blended attacks characteristic of Advanced Persistent Threats (APTs). This includes organisations in financial services, government, defence, critical infrastructure, healthcare, technology, and any sector handling high-value intellectual property or personally identifiable information.
Not when: Do not attempt to implement all elements of this pattern unless your organisation has high operational maturity with respect to change and configuration management.

## Controls (33, NIST SP 800-53 ids)
- Critical (5): AU-02, AU-06, CM-02, IR-05, SI-04
- Important (17): AC-02, AC-04, AU-01, AU-09, CM-03, CM-05, CM-06, IR-01, IR-03, RA-02, RA-03, RA-05, SA-08, SC-07, SI-03, SI-06, SI-07
- Standard (11): AC-17, AC-18, AC-20, AT-01, CA-02, CM-01, CP-10, RA-01, SA-03, SA-06, SA-07
- Withdrawn from SP 800-53 by NIST: SA-06 (now in CM-10, SI-07); SA-07 (now in CM-11, SI-07)

## What each critical control mitigates (5)
- AU-02 Event Logging: T-MD-001, T-MD-002, T-MD-004
- AU-06 Audit Record Review, Analysis, and Reporting: T-MD-001, T-MD-003, T-MD-004, T-MD-006, T-MD-008
- CM-02 Baseline Configuration: T-MD-005, T-MD-007
- IR-05 Incident Monitoring: T-MD-001, T-MD-005
- SI-04 System Monitoring: T-MD-001, T-MD-002, T-MD-003, T-MD-004, T-MD-005, T-MD-006, T-MD-008, T-MD-009

## Threats and the controls that mitigate them (10)
- T-MD-001 Advanced Persistent Threat (Multi-Stage Intrusion with Extended Dwell Time): SI-04, AU-06, AU-02, IR-05
- T-MD-002 Living-off-the-Land Attacks (Abuse of Legitimate System Tools): SI-04, CM-06, AU-02, SI-07
- T-MD-003 Credential-Based Attacks (Pass-the-Hash, Kerberoasting, Golden Ticket): AC-02, AU-06, SI-04, AC-04
- T-MD-004 Insider Threat (Data Theft or Sabotage by Authorised Users): AU-02, AU-06, AC-02, SI-04
- T-MD-005 Ransomware (Pre-Encryption Reconnaissance and Lateral Movement): SI-03, SI-04, IR-05, CM-02
- T-MD-006 Data Exfiltration via Encrypted Channels or Covert Channels: SC-07, AC-04, SI-04, AU-06
- T-MD-007 Configuration Drift and Unauthorised System Changes: CM-02, CM-03, CM-06, SI-07
- T-MD-008 Zero-Day Exploitation (Signature Evasion): SI-04, SI-06, RA-05, AU-06
- T-MD-009 Supply Chain Compromise (Tampered Updates or Backdoored Dependencies): SI-07, CM-05, SA-08, SI-04
- T-MD-010 Security Control Tampering or Evasion: SI-06, AU-09, SI-07, CM-05

## More
- The critical controls and what each mitigates, as JSON (a few KB): /api/v1/patterns/SP-025/crosswalk?emphasis=critical
- The same for every control, with its clauses in a framework: /api/v1/patterns/SP-025/crosswalk?framework={framework id}. Framework ids are listed in /llms.txt
- The pattern's prose, examples and references as JSON, 28 KB: /api/v1/patterns/SP-025
- Page for people: /patterns/sp-025/
- Related: SP-017 Secure Network Zone Module; SP-014 Awareness and Training Pattern; SP-018 Information Security Management System; SP-023 Industrial Control Systems; SP-026 PCI Full Environment

This card, the API and the page are generated from one file. Checking one against another adds no evidence.
