---
title: "ISO 27001: 2022 A.8.16 Monitoring activities"
description: "This article provides additional information on how you can meet the requirement for the ISO 27001: 2022 control A.8.16 Monitoring activities."
---

[Skip to content](https://knowledge.adoptech.co.uk/a.8.16-monitoring-activities#main-content)

[![Adoptech-logo-GreyWithoutStrapline-1.png\]](https://knowledge.adoptech.co.uk/hs-fs/hubfs/Adoptech-logo-GreyWithoutStrapline-1.png?height=39&name=Adoptech-logo-GreyWithoutStrapline-1.png)](https://knowledge.adoptech.co.uk/?hsLang=en)

Open main navigation

Close main navigation

 Adoptech Help Centre

- There are no suggestions because the search field is empty.

1. [Knowledge base](https://knowledge.adoptech.co.uk/?hsLang=en)
2. [Frameworks & Certifications](https://knowledge.adoptech.co.uk/frameworks-certifications?hsLang=en)
3. [ISO 27001](https://knowledge.adoptech.co.uk/frameworks-certifications?hsLang=en#iso-27001)

# ISO 27001: 2022 A.8.16 Monitoring activities

## This article provides additional information on how you can meet the requirement for the ISO 27001: 2022 control A.8.16 Monitoring activities.

### **ISO 27001: 2022 Control Description**

Networks, systems and applications shall be monitored for anomalous  behaviour and appropriate actions taken to evaluate potential information security incidents.

### Purpose

To detect unusual behaviour and identify potential information security incidents.

### **Guidance on implementation**

#### Setting Up Monitoring

1. Determine Monitoring Scope: 
     - Define what needs to be monitored based on your business and security requirements. Make sure to consider relevant laws and regulations. Retain monitoring records for a set period, as determined by your organisation.
2. What to Monitor: 
     - Consider including the following in your monitoring system: 
           - Inbound and outbound network, system, and application traffic.
           - Access to systems, servers, networking equipment, monitoring systems, and critical applications.
           - Critical system and network configuration files, especially those with admin-level access.
           - Logs from security tools such as antivirus, intrusion detection systems (IDS), firewalls, and data leakage prevention systems.
           - Event logs related to system and network activities.
           - The execution of authorised code and verification that it hasn’t been tampered with.
           - Resource usage (e.g. CPU, memory, bandwidth) and their performance levels.

#### Establishing a Baseline

1. Create a Baseline: 
     - Establish what normal behaviour looks like in your systems. This will help identify anything out of the ordinary. When creating a baseline, consider: 
           - System usage during both normal and peak periods.
           - Typical access times, locations, and frequencies for users or groups of users.
2. Identify Anomalous Behaviour: 
     - Configure your monitoring system to detect behaviour that deviates from the baseline, such as: 
           - Unexpected termination of processes or applications.
           - Activity linked to malware or connections from known malicious IP addresses.
           - Known attack patterns (e.g. denial of service, buffer overflows).
           - Unusual system activities (e.g. keystroke logging, process injection).
           - Bottlenecks and network issues (e.g. high latency, jitter).
           - Unauthorised access attempts to systems or data.
           - Unauthorised scanning of applications, systems, and networks.
           - Unusual user or system actions that differ from the expected behaviour.

#### Implementing Continuous Monitoring

1. Use Real-Time Monitoring: 
     - Employ monitoring tools that continuously watch for anomalies, either in real time or at regular intervals, depending on your organisation's needs and capabilities. Choose tools that can: 
           - Handle large data volumes.
           - Adapt to evolving threats.
           - Provide real-time alerts.
           - Recognise specific signatures and behaviour patterns in data, networks, or applications.
2. Automate Alerts: 
     - Configure your monitoring software to automatically generate alerts when predefined thresholds are crossed. Alerts can be sent through management consoles, emails, or instant messaging. Ensure that: 
           - The alert system is fine-tuned to reduce false positives.
           - Staff are trained to respond effectively to alerts and interpret potential incidents.
           - Redundant systems and processes are in place to handle alert notifications.

#### Responding to Anomalies

1. Communicate and Act: 
     - Report abnormal events to relevant teams to improve security audits, evaluations, vulnerability scans, and monitoring. Ensure procedures are in place to: 
           - Respond quickly to positive indicators from the monitoring system to minimise the impact of security events.
           - Identify and address false positives, and adjust the monitoring software to reduce them in the future.

### Additional Information

- Enhancing Security Monitoring: 
    - Consider enhancing your monitoring by: 
          - Using threat intelligence systems.
          - Leveraging machine learning and artificial intelligence.
          - Implementing blocklists or allowlists.
          - Conducting technical security assessments (e.g. vulnerability assessments, penetration tests) to help set baselines.
          - Using performance monitoring tools to detect unusual behaviour.
          - Combining log analysis with monitoring systems.
- Botnet Detection: 
    - Monitor for unusual communications, which could indicate a botnet (a group of compromised devices used for attacks like distributed denial of service). If an infected device is communicating with a controller, take immediate action to address the issue.

 

- [Getting Started](https://knowledge.adoptech.co.uk/getting-started?hsLang=en#main-content)

    - [Getting Started](https://knowledge.adoptech.co.uk/getting-started?hsLang=en#getting-started)
    - [Accounts & Billing](https://knowledge.adoptech.co.uk/getting-started?hsLang=en#accounts-billing)
- [FAQ's on Adoptech](https://knowledge.adoptech.co.uk/faqs-on-adoptech?hsLang=en#main-content)

    - [Frameworks](https://knowledge.adoptech.co.uk/faqs-on-adoptech?hsLang=en#frameworks)
    - [Policies & Documents](https://knowledge.adoptech.co.uk/faqs-on-adoptech?hsLang=en#policies-documents)
    - [Risk Management](https://knowledge.adoptech.co.uk/faqs-on-adoptech?hsLang=en#risk-management)
    - [Supplier Management](https://knowledge.adoptech.co.uk/faqs-on-adoptech?hsLang=en#supplier-management)
    - [Audit Preparation](https://knowledge.adoptech.co.uk/faqs-on-adoptech?hsLang=en#audit-preparation)
    - [Trust Centre](https://knowledge.adoptech.co.uk/faqs-on-adoptech?hsLang=en#trust-centre)
    - [User Management](https://knowledge.adoptech.co.uk/faqs-on-adoptech?hsLang=en#user-management)
- [Frameworks & Certifications](https://knowledge.adoptech.co.uk/frameworks-certifications?hsLang=en#main-content)

    - [ISO 27001](https://knowledge.adoptech.co.uk/frameworks-certifications?hsLang=en#iso-27001)
    - [ISO 42001](https://knowledge.adoptech.co.uk/frameworks-certifications?hsLang=en#iso-42001)
    - [Cyber Essentials](https://knowledge.adoptech.co.uk/frameworks-certifications?hsLang=en#cyber-essentials)
    - [CAF](https://knowledge.adoptech.co.uk/frameworks-certifications?hsLang=en#caf)
    - [PCI-DSS](https://knowledge.adoptech.co.uk/frameworks-certifications?hsLang=en#pci-dss)
    - [SOC2](https://knowledge.adoptech.co.uk/frameworks-certifications?hsLang=en#soc2)
    - [Data Privacy (GDPR)](https://knowledge.adoptech.co.uk/frameworks-certifications?hsLang=en#data-privacy-gdpr)
    - [DORA](https://knowledge.adoptech.co.uk/frameworks-certifications?hsLang=en#dora)
    - [ISO 9001](https://knowledge.adoptech.co.uk/frameworks-certifications?hsLang=en#iso-9001)
    - [ISO 22301](https://knowledge.adoptech.co.uk/frameworks-certifications?hsLang=en#iso-22301)
    - [ISO 14001](https://knowledge.adoptech.co.uk/frameworks-certifications?hsLang=en#iso-14001)
    - [NIST 800-53](https://knowledge.adoptech.co.uk/frameworks-certifications?hsLang=en#nist-800-53)
    - [NIST-CSF](https://knowledge.adoptech.co.uk/frameworks-certifications?hsLang=en#nist-csf)
    - [NIS2](https://knowledge.adoptech.co.uk/frameworks-certifications?hsLang=en#nis2)
    - [ISO 20000-1](https://knowledge.adoptech.co.uk/frameworks-certifications?hsLang=en#iso-20000-1)
    - [HIPAA](https://knowledge.adoptech.co.uk/frameworks-certifications?hsLang=en#hipaa)
- [Integrations](https://knowledge.adoptech.co.uk/integrations?hsLang=en#main-content)

    - [Cloud Infrastructure](https://knowledge.adoptech.co.uk/integrations?hsLang=en#cloud-infrastructure)
    - [Identity & Access](https://knowledge.adoptech.co.uk/integrations?hsLang=en#identity-access)
    - [DevOps & Code](https://knowledge.adoptech.co.uk/integrations?hsLang=en#devops-code)
    - [Project Management](https://knowledge.adoptech.co.uk/integrations?hsLang=en#project-management)
    - [HR & People Systems](https://knowledge.adoptech.co.uk/integrations?hsLang=en#hr-people-systems)
    - [Security & Devices](https://knowledge.adoptech.co.uk/integrations?hsLang=en#security-devices)
    - [Communication & Collaboration](https://knowledge.adoptech.co.uk/integrations?hsLang=en#communication-collaboration)
- [Legal & Regulations](https://knowledge.adoptech.co.uk/legal-regulations?hsLang=en)
- [Security Guidance](https://knowledge.adoptech.co.uk/security-guidance?hsLang=en)
- [Troubleshooting](https://knowledge.adoptech.co.uk/troubleshooting?hsLang=en)

[![Chill listening crop-3](https://knowledge.adoptech.co.uk/hs-fs/hubfs/adoptech-logo-1.png?width=209&height=54&name=adoptech-logo-1.png "Chill listening crop-3")](https://adoptech.co.uk/)

<https://uk.linkedin.com/company/adoptech>

Copyright © 2026, Adoptech Ltd.