πΌ SI-4 System Monitoring (L)(M)(H)
- Contextual name: πΌ SI-4 System Monitoring (L)(M)(H)
- ID:
/frameworks/fedramp-moderate-security-controls/si/04
- Located in: πΌ System and Information Integrity
Descriptionβ
a. Monitor the system to detect:
-
Attacks and indicators of potential attacks in accordance with the following monitoring objectives: [Assignment: organization-defined monitoring objectives]; and
-
Unauthorized local, network, and remote connections;
b. Identify unauthorized use of the system through the following techniques and methods: [Assignment: organization-defined techniques and methods];
c. Invoke internal monitoring capabilities or deploy monitoring devices:
-
Strategically within the system to collect organization-determined essential information; and
-
At ad hoc locations within the system to track specific types of transactions of interest to the organization;
d. Analyze detected events and anomalies;
e. Adjust the level of system monitoring activity when there is a change in risk to organizational operations and assets, individuals, other organizations, or the Nation;
f. Obtain legal opinion regarding system monitoring activities; and
g. Provide [Assignment: organization-defined system monitoring information] to [Assignment: organization-defined personnel or roles] [Selection (one-or-more): as needed; [Assignment: organization-defined frequency]].
SI-4 Additional FedRAMP Requirements and Guidance:
Guidance: See US-CERT Incident Response Reporting Guidelines.
Similarβ
- Sections
/frameworks/fedramp-high-security-controls/si/04
- Internal
- ID:
dec-c-d2e87396
- ID:
Similar Sections (Take Policies From)β
Section | Sub Sections | Internal Rules | Policies | Flags |
---|---|---|---|---|
πΌ FedRAMP High Security Controls β πΌ SI-4 System Monitoring (L)(M)(H) | 14 | 48 | 51 |
Sub Sectionsβ
Policies (7)β
Policy | Logic Count | Flags |
---|---|---|
π AWS Account Multi-Region CloudTrail is not enabled π’ | 1 | π’ x6 |
π AWS CloudTrail Log File Validation is not enabled π’ | 1 | π’ x6 |
π Azure PostgreSQL Flexible Server connection_throttle.enable Parameter is not set to ON π’ | 1 | π’ x6 |
π Azure SQL Server Auditing is not enabled π’ | 1 | π’ x6 |
π Azure SQL Server Auditing Retention is less than 90 days π’ | 1 | π’ x6 |
π Azure Storage Blob Logging is not enabled for Read, Write, and Delete requests π’ | 1 | π’ x6 |
π Azure Storage Queue Logging is not enabled for Read, Write, and Delete requests π’ | 1 | π’ x6 |