💼 SI-3(8) Malicious Code Protection | Detect Unauthorized Commands
- ID:
/frameworks/nist-sp-800-53-r5/si/03/08
Stats
not available
Description
(a) Detect the following unauthorized operating system commands through the kernel application programming interface on [Assignment: organization-defined system hardware components]: [Assignment: organization-defined unauthorized operating system commands]; and (b) [Selection (one or more): issue a warning; audit the command execution; prevent the execution of the command].
Similar
- Sections
/frameworks/aws-fsbp-v1.0.0/cloudfront/05/frameworks/aws-fsbp-v1.0.0/cloudtrail/01/frameworks/aws-fsbp-v1.0.0/cloudtrail/05/frameworks/aws-fsbp-v1.0.0/codebuild/04/frameworks/aws-fsbp-v1.0.0/dms/07/frameworks/aws-fsbp-v1.0.0/dms/08/frameworks/aws-fsbp-v1.0.0/documentdb/04/frameworks/aws-fsbp-v1.0.0/ec2/51/frameworks/aws-fsbp-v1.0.0/eks/08/frameworks/aws-fsbp-v1.0.0/es/04/frameworks/aws-fsbp-v1.0.0/es/05/frameworks/aws-fsbp-v1.0.0/guardduty/01/frameworks/aws-fsbp-v1.0.0/neptune/02/frameworks/aws-fsbp-v1.0.0/network-firewall/02/frameworks/aws-fsbp-v1.0.0/opensearch/04/frameworks/aws-fsbp-v1.0.0/opensearch/05/frameworks/aws-fsbp-v1.0.0/route-53/02/frameworks/aws-fsbp-v1.0.0/rds/09/frameworks/aws-fsbp-v1.0.0/rds/34/frameworks/aws-fsbp-v1.0.0/rds/40/frameworks/aws-fsbp-v1.0.0/rds/42/frameworks/aws-fsbp-v1.0.0/rds/45/frameworks/aws-fsbp-v1.0.0/redshift/04/frameworks/aws-fsbp-v1.0.0/s3/09/frameworks/aws-fsbp-v1.0.0/transfer-family/03
- Internal
- ID:
dec-c-5a08767a
- ID:
Similar Sections (Take Policies From)
Sub Sections
| Section | Sub Sections | Internal Rules | Policies | Flags | Compliance |
|---|
Policies (13)
| Policy | Logic Count | Flags | Compliance |
|---|---|---|---|
| 🛡️ AWS Account Multi-Region CloudTrail is not enabled🟢 | 1 | 🟢 x6 | no data |
| 🛡️ AWS CloudFront Distribution Logging is not enabled🟢 | 1 | 🟢 x6 | no data |
| 🛡️ AWS CloudTrail S3 Bucket Access Logging is not enabled.🟢 | 1 | 🟢 x6 | no data |
| 🛡️ AWS CloudTrail Trail is not integrated with CloudWatch Logs🟢 | 1 | 🟠 x1, 🟢 x5 | no data |
| 🛡️ AWS DMS Migration Task Logging is not enabled🟢 | 1 | 🟢 x6 | no data |
| 🛡️ AWS EKS Cluster Logging is not enabled for all control plane logs types🟢 | 1 | 🟢 x6 | no data |
| 🛡️ AWS GuardDuty is not enabled in all regions🟢 | 1 | 🟢 x6 | no data |
| 🛡️ AWS OpenSearch Domain audit logging is not enabled🟢 | 1 | 🟢 x6 | no data |
| 🛡️ AWS OpenSearch Domain error logging is not enabled🟢 | 1 | 🟢 x6 | no data |
| 🛡️ AWS RDS Cluster required log exports to CloudWatch Logs are not enabled🟢 | 1 | 🟢 x6 | no data |
| 🛡️ AWS RDS Instance database logging is not enabled🟢 | 1 | 🟢 x6 | no data |
| 🛡️ AWS Redshift Cluster Audit Logging is not enabled🟢 | 1 | 🟢 x6 | no data |
| 🛡️ AWS S3 Bucket Server Access Logging is not enabled🟢 | 1 | 🟢 x6 | no data |