πΌ SI-4 System Monitoring
- Contextual name: πΌ SI-4 System Monitoring
- ID:
/frameworks/nist-sp-800-53-r5/si/04
- Located in: πΌ SI System And Information Integrity
Descriptionβ
a. Monitor the system to detect:
- Attacks and indicators of potential attacks in accordance with the following monitoring objectives: [Assignment: organization-defined monitoring objectives]; and
- Unauthorized local, network, and remote connections; b. Identify unauthorized use of the system through the following techniques and methods: [Assignment: organization-defined techniques and methods]; c. Invoke internal monitoring capabilities or deploy monitoring devices:
- Strategically within the system to collect organization-determined essential information; and
- At ad hoc locations within the system to track specific types of transactions of interest to the organization; d. Analyze detected events and anomalies; e. Adjust the level of system monitoring activity when there is a change in risk to organizational operations and assets, individuals, other organizations, or the Nation; f. Obtain legal opinion regarding system monitoring activities; and g. Provide [Assignment: organization-defined system monitoring information] to [Assignment: organization-defined personnel or roles] [Selection (one or more): as needed; [Assignment: organization-defined frequency]].
Similarβ
- Sections
/frameworks/aws-fsbp-v1.0.0/cloudtrail/04
/frameworks/aws-fsbp-v1.0.0/codebuild/04
/frameworks/aws-fsbp-v1.0.0/ec2/51
/frameworks/aws-fsbp-v1.0.0/eks/08
/frameworks/aws-fsbp-v1.0.0/guardduty/01
/frameworks/aws-fsbp-v1.0.0/macie/01
/frameworks/aws-fsbp-v1.0.0/macie/02
/frameworks/aws-fsbp-v1.0.0/mq/02
/frameworks/aws-fsbp-v1.0.0/network-firewall/02
/frameworks/aws-fsbp-v1.0.0/transfer-family/03
- Internal
- ID:
dec-c-a8e96a81
- ID:
Similar Sections (Take Policies From)β
Similar Sections (Give Policies To)β
Sub Sectionsβ
Policies (1)β
Policy | Logic Count | Flags |
---|---|---|
π AWS CloudTrail Log File Validation is not enabled π’ | 1 | π’ x6 |