Skip to main content
Category: Logging and Monitoring

Monitoring Activities Control (8.16)

Also known as: Annex A 8.16, Control 8.16, A.8.16 Monitoring Activities, ISO 27002 Control 8.16
Simply put

Control 8.16 is an ISO 27001/27002 reference control that requires organisations to actively watch their networks, systems, and applications so they can spot unusual or suspicious activity. The aim is to notice when something is going wrong quickly, rather than discovering a problem days later. Where anomalous behaviour is detected, the organisation is expected to respond and, if needed, activate an appropriate reaction.

Formal definition

Control 8.16 (Monitoring Activities), introduced in the ISO/IEC 27002:2022 revision and referenced in ISO/IEC 27001:2022 Annex A, is described in the source material as a detective and corrective control that modifies risk by optimising monitoring of networks, systems, and applications to identify anomalous behaviour and enable timely response. As an Annex A reference control, its inclusion is selected via the Statement of Applicability and informed by the organisation's risk assessment rather than being mandatory in every ISMS. Its scope covers ongoing observation to recognise unusual activity and, where warranted, trigger appropriate corrective action; it should be read alongside the certifiable ISMS requirements in clauses 4 through 10 and is distinct from the SOC 2 Trust Services Criteria. Control counts and structure cited here reflect the 2022 edition and differ from the 2013 version.

Why it matters

Many security incidents are not stopped by prevention alone; they are contained by early detection. Control 8.16 addresses the gap between something going wrong and someone actually noticing it. As one source frames it, monitoring is about ensuring you recognise a problem in real time rather than finding out days later when a customer calls. Without active observation of networks, systems, and applications, anomalous behaviour can persist undetected, giving an issue more time to escalate.

Because Control 8.16 is described as a dual-purpose detective and corrective control, it does more than surface alerts. It is intended to modify risk by both identifying unusual activity and enabling a timely, appropriate response where warranted. This combination matters because detection without response has limited value; the control ties observation to action, supporting an organisation's ability to react before a minor anomaly becomes a larger event.

It is important to keep expectations proportionate. As an ISO 27001:2022 Annex A reference control, 8.16 is selected via the Statement of Applicability and informed by the organisation's risk assessment, so its implementation depth typically varies by scope and risk profile. Monitoring reduces the likelihood of delayed detection, but it does not guarantee that every incident will be caught or prevented, and it should be read alongside the certifiable ISMS requirements in clauses 4 through 10.

Who it's relevant to

Security Engineers and SOC Analysts
Those responsible for operating monitoring tooling and investigating alerts implement the practical side of Control 8.16, observing networks, systems, and applications to detect anomalous behaviour and support timely response. The depth of tooling and coverage typically depends on the scope and risk assessment agreed for the ISMS.
ISMS Managers and GRC Professionals
Individuals maintaining the ISMS decide, through the Statement of Applicability and risk assessment, whether and how Control 8.16 applies, since it is a reference control rather than a universal mandate. They also document how monitoring links to the certifiable requirements in clauses 4 through 10.
ISO 27001 Certification Auditors
Auditors from accredited certification bodies assess whether monitoring activities are implemented consistently with the organisation's stated scope and risk decisions. Because 8.16 was introduced in the 2022 revision, auditors typically reference the applicable edition when evaluating the control.
Incident Response Teams
Given the control's corrective dimension, responders benefit from the timely detection it is designed to enable, activating an appropriate reaction when anomalous behaviour is identified. The effectiveness of this handoff depends on how detection and response processes are scoped and connected.

Inside Monitoring Activities Control (8.16)

Control Reference (8.16)
Monitoring Activities is control 8.16 within the technological controls theme of ISO/IEC 27001:2022 Annex A. As an Annex A reference control, it is selected for applicability through the Statement of Applicability and informed by the organization's risk assessment, rather than being universally mandatory.
Network and System Monitoring
The control addresses monitoring of networks, systems, and applications for anomalous behavior. In most implementations this involves collecting and reviewing activity across the ISMS scope to detect potential security events.
Anomaly and Baseline Detection
Monitoring typically involves establishing a baseline of expected behavior so deviations can be identified. Depending on scope, organizations may define what constitutes normal activity to support detection of unusual patterns.
Evaluation and Response Linkage
Detected anomalies are intended to be evaluated against defined criteria and, where relevant, escalated to incident management processes. The control commonly connects monitoring outputs to broader response and evaluation activities.
Scope Dependency
How monitoring is designed and operated depends on the defined ISMS scope, the organization's risk assessment, and the decisions recorded in the Statement of Applicability.

Common questions

Answers to the questions practitioners most commonly ask about Monitoring Activities Control (8.16).

Is control 8.16 a SOC 2 requirement?
No. Control 8.16 (Monitoring Activities) is a reference control in Annex A of ISO/IEC 27001 (2022 revision), where it appears within the technological controls theme. It is not part of the SOC 2 framework. SOC 2 examinations are structured around the Trust Services Criteria, with Security (the Common Criteria) being required and Availability, Processing Integrity, Confidentiality, and Privacy selected based on scope. While the concept of monitoring may be addressed by controls in a SOC 2 examination and could map partially to 8.16, the two frameworks are distinct, and the numbered Annex A reference is specific to ISO 27001. Mapping between the frameworks is possible but partial.
Does implementing control 8.16 mean my ISO 27001 certification is guaranteed once monitoring is in place?
No. Control 8.16 is one of the reference controls listed in Annex A, which is selected via the Statement of Applicability and informed by risk assessment. The certifiable requirements of ISO 27001 are in clauses 4 through 10, which define the information security management system (ISMS). An Annex A control being in place does not by itself confer certification; certification is issued by an accredited certification body against the overall ISMS. Additionally, any resulting certificate covers only the defined scope of the ISMS, and outcomes depend on the certification body, scope, and risk assessment.
How do organizations typically decide what to monitor under control 8.16?
In most implementations, the scope of monitoring is derived from the organization's risk assessment and the requirements identified in the ISMS clauses. Organizations typically consider networks, systems, and applications relevant to their defined scope and identify baselines of expected behavior so that anomalies can be detected. Because Annex A controls are selected and tailored through the Statement of Applicability, what is monitored depends on the organization's context, its risk appetite, and the scope of the ISMS rather than a single prescribed approach.
What evidence is generally useful to demonstrate control 8.16 during an audit?
Depending on the certification body and the auditor, organizations commonly maintain records such as monitoring configurations, defined baselines or thresholds, logs of detected events, and documentation of how anomalies are reviewed and escalated. Evidence that monitoring is operating consistently and is reviewed over time tends to be helpful. The specific evidence expected can vary by scope and by the certification body, so it is advisable to align documentation with the organization's own Statement of Applicability and procedures.
How does control 8.16 relate to incident response activities?
Monitoring activities typically serve as an input to incident detection and response, since anomalies or indicators identified through monitoring may trigger further investigation or an incident response process. In most implementations, organizations connect monitoring outputs to their escalation and response procedures so that detected events are acted upon. The precise interaction depends on how the organization has designed its ISMS and related controls, and other Annex A controls may also be relevant to the overall response workflow.
How often should monitoring under control 8.16 be reviewed or tuned?
The standard does not fix a universal frequency. In most engagements, organizations review monitoring configurations, baselines, and thresholds periodically and after significant changes to systems, the environment, or the risk profile. The appropriate cadence depends on the organization's risk assessment, scope, and operational context. Documenting the chosen review approach and demonstrating that it is followed is generally more important than adhering to any single prescribed interval.

Common misconceptions

Control 8.16 requires a specific tool such as a SIEM to be compliant.
The standard describes the objective of monitoring for anomalous behavior but does not mandate a particular product or technology. In most engagements the approach is selected based on scope and risk, and various methods may satisfy the intent depending on the certification body's assessment.
Implementing monitoring under ISO 27001 automatically satisfies SOC 2 monitoring expectations.
Mapping between ISO 27001 Annex A controls and the SOC 2 Trust Services Criteria (the Common Criteria) is possible but partial. Satisfying control 8.16 does not automatically satisfy SOC 2 requirements, which are assessed through a separate attestation examination performed by a licensed CPA firm under SSAE 18.
Control 8.16 is a mandatory requirement that every certified organization must apply.
Annex A controls are reference controls selected via the Statement of Applicability and informed by risk assessment. The certifiable ISMS requirements reside in clauses 4 through 10; an organization may justify the applicability or exclusion of a given Annex A control based on its risk decisions, subject to review by the certification body.

Best practices

Document the applicability decision for control 8.16 in the Statement of Applicability and tie it to specific outcomes of your risk assessment.
Establish baselines of expected network, system, and application behavior so that anomalies can be identified against a defined reference point, adjusting the approach to your ISMS scope.
Define clear criteria for evaluating detected anomalies and link monitoring outputs to your incident management and response processes.
Retain evidence of monitoring activity and reviews to demonstrate ongoing operation to the certification body, recognizing that expectations may vary by auditor and scope.
Periodically review and tune monitoring coverage and thresholds to reflect changes in systems, threats, and the defined ISMS scope.
Remember that monitoring under 8.16 covers only the defined ISMS scope and does not by itself guarantee freedom from breaches, so coordinate it with other controls rather than treating it as a standalone safeguard.