KSI-MLA-OSM — Operating SIEM Capability

Official CR26 Key Security Indicator in the Monitoring, Logging, and Auditing family (KSI-MLA). The statement below is verbatim from the catalog.

Educational resource only. scm.cc is not a FedRAMP Recognized Independent Assessor (3PAO) and is not FedRAMP-authorized; it grants no authorization, certification, or assessment outcome. FedRAMP.gov is the authoritative source. This is not legal advice.

Official requirement

A Security Information and Event Management (SIEM) or similar system(s) is used and persistently reviewed for centralized, tamper-resistant logging of events, activities, and changes.

Assessment considerations

The official reference cites no related SP 800-53 controls for this indicator.

Static HTML reference: scm.cc/ksi/ksi-mla-osm/. Interactive view: KSI Explorer (in progress).

Related hub pages

Primary sources

Last verified 2026-09-27. FedRAMP.gov is authoritative.

Explore the knowledge hub