KSI-MLA-OSM - Monitoring, Logging, and Auditing
Operating SIEM Capability
Official statement
A Security Information and Event Management (SIEM) or similar system(s) is used and persistently reviewed for centralized, tamper-resistant logging of events, activities, and changes.
The official reference cites no related SP 800-53 controls for this indicator.
Other Monitoring, Logging, and Auditing indicators
- KSI-MLA-ALA - Authorizing Log Access
- KSI-MLA-EVC - Evaluating Configurations
- KSI-MLA-LET - Logging Event Types
- KSI-MLA-RVL - Reviewing Logs
Source: https://fedramp.gov/2026/reference/20x/c/key-security-indicators/. Pinned 2026-09-27 (catalog fedramp-20x-ksi/official-1.0.0-cr26). This page shows the list as pinned on that date. A weekly automated check flags any difference from the official page.