Why it matters
Logs nobody looks at don't actually detect anything — monitoring is what turns logs into an early warning.
How a self-led small team implements it
Basic alerting on your existing logging platform (failed logins, unusual access) is proportionate before investing in a SIEM.
What auditors expect to see
Alert configuration, example triggered alerts.
Track A.8.16 in your own Statement of Applicability — mark it applicable, log your justification, and link it to the risk that drove it.
Start your ISMS