Skip to main content
Implement systems to monitor and log third-party API connections, sessions, and data access

Control activities

Typical evidence

Should include?

Configuring logging for third-party interactions. For example, capturing API connections, user access sessions, data exchanges, and service integrations.

Capturing access metadata. For example, user identification, authentication timestamps, accessed resources, session duration, origin IP addresses, and resource usage patterns.

E009.1 Config: Third-party access monitoring

Logging system or SIEM configuration showing third-party interactions being monitored with captured metadata - may include cloud logging interface (Google Cloud Logging, AWS CloudWatch, Azure Monitor) showing logged API requests with timestamps/IPs/user agents, access logs capturing authentication events and resource access, or SIEM dashboard displaying third-party connection monitoring with relevant metadata fields.

Typical location
Engineering Tooling
Capabilities
Universal
May include?

Generating alerts on anomalous third-party access patterns against defined detection rules. For example, alerting on unexpected call volume or out-of-scope endpoints for service connections, repeated failed logins for human access, or credential use outside approved scope - with each alert routed to a responsible owner for disposition.

E009.2 Config: Anomalous third-party access alerting

Detection-rule or SIEM configuration for anomalous third-party access - may include alerting rules or correlation logic defining anomalous-access conditions, plus sample fired alerts showing disposition (case assignment, triage notes, or resolution records).

Typical location
Engineering Tooling
Capabilities
Universal

Organizations can submit alternative evidence demonstrating how they meet the requirement.