Monitoring Activities Control (8.16)
Control 8.16 is an ISO 27001/27002 reference control that requires organisations to actively watch their networks, systems, and applications so they can spot unusual or suspicious activity. The aim is to notice when something is going wrong quickly, rather than discovering a problem days later. Where anomalous behaviour is detected, the organisation is expected to respond and, if needed, activate an appropriate reaction.
Control 8.16 (Monitoring Activities), introduced in the ISO/IEC 27002:2022 revision and referenced in ISO/IEC 27001:2022 Annex A, is described in the source material as a detective and corrective control that modifies risk by optimising monitoring of networks, systems, and applications to identify anomalous behaviour and enable timely response. As an Annex A reference control, its inclusion is selected via the Statement of Applicability and informed by the organisation's risk assessment rather than being mandatory in every ISMS. Its scope covers ongoing observation to recognise unusual activity and, where warranted, trigger appropriate corrective action; it should be read alongside the certifiable ISMS requirements in clauses 4 through 10 and is distinct from the SOC 2 Trust Services Criteria. Control counts and structure cited here reflect the 2022 edition and differ from the 2013 version.
Why it matters
Many security incidents are not stopped by prevention alone; they are contained by early detection. Control 8.16 addresses the gap between something going wrong and someone actually noticing it. As one source frames it, monitoring is about ensuring you recognise a problem in real time rather than finding out days later when a customer calls. Without active observation of networks, systems, and applications, anomalous behaviour can persist undetected, giving an issue more time to escalate.
Because Control 8.16 is described as a dual-purpose detective and corrective control, it does more than surface alerts. It is intended to modify risk by both identifying unusual activity and enabling a timely, appropriate response where warranted. This combination matters because detection without response has limited value; the control ties observation to action, supporting an organisation's ability to react before a minor anomaly becomes a larger event.
It is important to keep expectations proportionate. As an ISO 27001:2022 Annex A reference control, 8.16 is selected via the Statement of Applicability and informed by the organisation's risk assessment, so its implementation depth typically varies by scope and risk profile. Monitoring reduces the likelihood of delayed detection, but it does not guarantee that every incident will be caught or prevented, and it should be read alongside the certifiable ISMS requirements in clauses 4 through 10.
Who it's relevant to
Inside Monitoring Activities Control (8.16)
Common questions
Answers to the questions practitioners most commonly ask about Monitoring Activities Control (8.16).