Knowledge is Power

Sitewide Search

Search Bare Metal Cyber

Search courses, individual lessons, wiki entries, books, podcasts, magazine articles, Daily Cyber News, and Darwin.

NIST SP 800-53 Learning Center

SI-4 — System Monitoring

Read the official control and assessment content, then use the separately labeled Bare Metal Cyber perspective to connect the requirement to implementation, evidence, and sustained operation.

25Enhancements
6Parameters
3Baseline memberships
3Assessment methods

SI — System and Information Integrity · NIST SP 800-53 Release 5.2.0

LowModerateHigh
Official NIST control content

Control statement

  1. a.Monitor the system to detect:
    1. 1.Attacks and indicators of potential attacks in accordance with the following monitoring objectives: [Organization-defined: monitoring objectives] ; and
    2. 2.Unauthorized local, network, and remote connections;
  2. b.Identify unauthorized use of the system through the following techniques and methods: [Organization-defined: techniques and methods];
  3. c.Invoke internal monitoring capabilities or deploy monitoring devices:
    1. 1.Strategically within the system to collect organization-determined essential information; and
    2. 2.At ad hoc locations within the system to track specific types of transactions of interest to the organization;
  4. d.Analyze detected events and anomalies;
  5. e.Adjust the level of system monitoring activity when there is a change in risk to organizational operations and assets, individuals, other organizations, or the Nation;
  6. f.Obtain legal opinion regarding system monitoring activities; and
  7. g.Provide [Organization-defined: system monitoring information] to [Organization-defined: personnel or roles] [Organization-defined: si-04_odp.05].
Official NIST discussion

Discussion

System monitoring includes external and internal monitoring. External monitoring includes the observation of events occurring at external interfaces to the system. Internal monitoring includes the observation of events occurring within the system. Organizations monitor systems by observing audit activities in real time or by observing other system aspects such as access patterns, characteristics of access, and other actions. The monitoring objectives guide and inform the determination of the events. System monitoring capabilities are achieved through a variety of tools and techniques, including intrusion detection and prevention systems, malicious code protection software, scanning tools, audit record monitoring software, and network monitoring software. Depending on the security architecture, the distribution and configuration of monitoring devices may impact throughput at key internal and external boundaries as well as at other locations across a network due to the introduction of network throughput latency. If throughput management is needed, such devices are strategically located and deployed as part of an established organization-wide security architecture. Strategic locations for monitoring devices include selected perimeter locations and near key servers and server farms that support critical applications. Monitoring devices are typically employed at the managed interfaces associated with controls [SC-7](#sc-7) and [AC-17](#ac-17) . The information collected is a function of the organizational monitoring objectives and the capability of systems to support such objectives. Specific types of transactions of interest include Hypertext Transfer Protocol (HTTP) traffic that bypasses HTTP proxies. System monitoring is an integral part of organizational continuous monitoring and incident response programs, and output from system monitoring serves as input to those programs. System monitoring requirements, including the need for specific types of system monitoring, may be referenced in other controls (e.g., [AC-2g](#ac-2_smt.g), [AC-2(7)](#ac-2.7), [AC-2(12)(a)](#ac-2.12_smt.a), [AC-17(1)](#ac-17.1), [AU-13](#au-13), [AU-13(1)](#au-13.1), [AU-13(2)](#au-13.2), [CM-3f](#cm-3_smt.f), [CM-6d](#cm-6_smt.d), [MA-3a](#ma-3_smt.a), [MA-4a](#ma-4_smt.a), [SC-5(3)(b)](#sc-5.3_smt.b), [SC-7a](#sc-7_smt.a), [SC-7(24)(b)](#sc-7.24_smt.b), [SC-18b](#sc-18_smt.b), [SC-43b](#sc-43_smt.b) ). Adjustments to levels of system monitoring are based on law enforcement information, intelligence information, or other sources of information. The legality of system monitoring activities is based on applicable laws, executive orders, directives, regulations, policies, standards, and guidelines.

Official OSCAL parameters

Organization-defined parameters

These values must be resolved through the organization’s tailoring and governance process. Bracketed parameter references in the control text identify where a decision is required.

monitoring objectivesmonitoring objectives to detect attacks and indicators of potential attacks on the system are defined;
techniques and methodstechniques and methods used to identify unauthorized use of the system are defined;
system monitoring informationsystem monitoring information to be provided to personnel or roles is defined;
personnel or rolespersonnel or roles to whom system monitoring information is to be provided is/are defined;
si-04_odp.05
frequencya frequency for providing system monitoring to personnel or roles is defined (if selected);
Original Bare Metal Cyber perspective

From control text to operational evidence

Use System Monitoring as a testable risk decision. Translate the official statement into accountable people, repeatable processes, configured technology, and evidence that demonstrates the outcome over time. In this family, pay particular attention to flaw remediation, malicious-code protection, monitoring, integrity, and trustworthy information handling.

Implementation workflow

  • Define the control boundary, responsible owner, inherited portions, and systems or processes in scope.
  • Resolve each organization-defined parameter before declaring the control implemented.
  • Document how the implementation satisfies every clause of the official control statement.
  • Collect evidence as a normal byproduct of operation rather than only before an assessment.
  • Review exceptions, changes, and monitoring results on a risk-based cadence.

Evidence examples

  • patch and remediation records
  • malware protection configuration
  • monitoring alerts and response records
  • integrity validation and exception reports

Common failure patterns

  • patch compliance hides unsupported assets
  • alerts generated without response ownership
  • exceptions never expire
  • integrity monitoring excludes critical configurations

Questions practitioners should ask

  • What risk decision is this control intended to support in this system?
  • Which parts are implemented locally, inherited, shared, or not applicable—and what evidence supports that decision?
  • Do the documented narrative, deployed configuration, operating process, and collected evidence agree?
  • What event or threshold requires the implementation to be reviewed or changed?
Official NIST SP 800-53A content

Assessment objectives and methods

Show the assessment objective
  1. SI-04a.
    1. SI-04a.01the system is monitored to detect attacks and indicators of potential attacks in accordance with [Organization-defined: monitoring objectives];
    2. SI-04a.02
      1. SI-04a.02[01]the system is monitored to detect unauthorized local connections;
      2. SI-04a.02[02]the system is monitored to detect unauthorized network connections;
      3. SI-04a.02[03]the system is monitored to detect unauthorized remote connections;
  2. SI-04b.unauthorized use of the system is identified through [Organization-defined: techniques and methods];
  3. SI-04c.
    1. SI-04c.01internal monitoring capabilities are invoked or monitoring devices are deployed strategically within the system to collect organization-determined essential information;
    2. SI-04c.02internal monitoring capabilities are invoked or monitoring devices are deployed at ad hoc locations within the system to track specific types of transactions of interest to the organization;
  4. SI-04d.
    1. SI-04d.[01]detected events are analyzed;
    2. SI-04d.[02]detected anomalies are analyzed;
  5. SI-04e.the level of system monitoring activity is adjusted when there is a change in risk to organizational operations and assets, individuals, other organizations, or the Nation;
  6. SI-04f.a legal opinion regarding system monitoring activities is obtained;
  7. SI-04g.[Organization-defined: system monitoring information] is provided to [Organization-defined: personnel or roles] [Organization-defined: si-04_odp.05].

Examine

  • System and information integrity policy
  • system and information integrity procedures
  • procedures addressing system monitoring tools and techniques
  • continuous monitoring strategy
  • facility diagram/layout
  • system design documentation
  • system monitoring tools and techniques documentation
  • locations within the system where monitoring devices are deployed
  • system configuration settings and associated documentation
  • system security plan
  • other relevant documents or records

Interview

  • System/network administrators
  • organizational personnel with information security responsibilities
  • organizational personnel installing, configuring, and/or maintaining the system
  • organizational personnel responsible for monitoring the system

Test

  • Organizational processes for system monitoring
  • mechanisms supporting and/or implementing system monitoring capabilities
Official relationships

Related controls

These relationships come from the official OSCAL catalog. They indicate useful dependencies or context, not automatic inheritance or equivalence.

MITRE D3FEND semantic mapping

Related defensive techniques

D3FEND maps this base control or one of its enhancements to the following defensive techniques. The ontology relation label is preserved and does not by itself prove implementation or effectiveness.

MITRE D3FEND™ and the D3FEND logo are trademarks of The MITRE Corporation. Bare Metal Cyber is not affiliated with or endorsed by MITRE.

Official NIST enhancements

Control enhancements

Enhancements add specificity, strength, or scope to the base control. Baseline badges show explicit selections in the official SP 800-53B OSCAL profiles.

Official NIST control enhancement

SI-4(1) — System-wide Intrusion Detection System

Connect and configure individual intrusion detection tools into a system-wide intrusion detection system.

Official discussion

Linking individual intrusion detection tools into a system-wide intrusion detection system provides additional coverage and effective detection capabilities. The information contained in one intrusion detection tool can be shared widely across the organization, making the system-wide detection capability more robust and powerful.

Assessment objectives and methods
  1. SI-04(01)[01]individual intrusion detection tools are connected to a system-wide intrusion detection system;
  2. SI-04(01)[02]individual intrusion detection tools are configured into a system-wide intrusion detection system.

Examine

  • System and information integrity policy
  • system and information integrity procedures
  • procedures addressing system monitoring tools and techniques
  • system design documentation
  • system monitoring tools and techniques documentation
  • system configuration settings and associated documentation
  • system audit records
  • system security plan
  • other relevant documents or records

Interview

  • System/network administrators
  • organizational personnel with information security responsibilities
  • organizational personnel installing, configuring, and/or maintaining the system
  • organizational personnel responsible for monitoring the system
  • organizational personnel responsible for the intrusion detection system

Test

  • Organizational processes for intrusion detection and system monitoring
  • mechanisms supporting and/or implementing intrusion detection capabilities
Official NIST control enhancement

SI-4(2) — Automated Tools and Mechanisms for Real-time Analysis

ModerateHigh

Employ automated tools and mechanisms to support near real-time analysis of events.

Official discussion

Automated tools and mechanisms include host-based, network-based, transport-based, or storage-based event monitoring tools and mechanisms or security information and event management (SIEM) technologies that provide real-time analysis of alerts and notifications generated by organizational systems. Automated monitoring techniques can create unintended privacy risks because automated controls may connect to external or otherwise unrelated systems. The matching of records between these systems may create linkages with unintended consequences. Organizations assess and document these risks in their privacy impact assessment and make determinations that are in alignment with their privacy program plan.

Assessment objectives and methods

automated tools and mechanisms are employed to support a near real-time analysis of events.

Examine

  • System and information integrity policy
  • system and information integrity procedures
  • procedures addressing system monitoring tools and techniques
  • system design documentation
  • system monitoring tools and techniques documentation
  • system configuration settings and associated documentation
  • system audit records
  • system security plan
  • privacy plan
  • privacy program plan
  • privacy impact assessment
  • privacy risk management documentation
  • other relevant documents or records

Interview

  • System/network administrators
  • organizational personnel with information security and privacy responsibilities
  • organizational personnel installing, configuring, and/or maintaining the system
  • organizational personnel responsible for monitoring the system
  • organizational personnel responsible for incident response/management

Test

  • Organizational processes for the near real-time analysis of events
  • organizational processes for system monitoring
  • mechanisms supporting and/or implementing system monitoring
  • mechanisms/tools supporting and/or implementing an analysis of events
Related controls
Official NIST control enhancement

SI-4(3) — Automated Tool and Mechanism Integration

Employ automated tools and mechanisms to integrate intrusion detection tools and mechanisms into access control and flow control mechanisms.

Official discussion

Using automated tools and mechanisms to integrate intrusion detection tools and mechanisms into access and flow control mechanisms facilitates a rapid response to attacks by enabling the reconfiguration of mechanisms in support of attack isolation and elimination.

Assessment objectives and methods
  1. SI-04(03)[01]automated tools and mechanisms are employed to integrate intrusion detection tools and mechanisms into access control mechanisms;
  2. SI-04(03)[02]automated tools and mechanisms are employed to integrate intrusion detection tools and mechanisms into flow control mechanisms.

Examine

  • System and information integrity policy
  • system and information integrity procedures
  • access control policy and procedures
  • procedures addressing system monitoring tools and techniques
  • system design documentation
  • system monitoring tools and techniques documentation
  • system configuration settings and associated documentation
  • system audit records
  • system security plan
  • other relevant documents or records

Interview

  • System/network administrators
  • organizational personnel with information security responsibilities
  • organizational personnel installing, configuring, and/or maintaining the system
  • organizational personnel responsible for monitoring the system
  • organizational personnel responsible for the intrusion detection system

Test

  • Organizational processes for intrusion detection and system monitoring
  • mechanisms supporting and/or implementing the intrusion detection and system monitoring capability
  • mechanisms and tools supporting and/or implementing the access and flow control capabilities
  • mechanisms and tools supporting and/or implementing the integration of intrusion detection tools into the access and flow control mechanisms
Related controls
Official NIST control enhancement

SI-4(4) — Inbound and Outbound Communications Traffic

ModerateHigh
  1. (a)Determine criteria for unusual or unauthorized activities or conditions for inbound and outbound communications traffic;
  2. (b)Monitor inbound and outbound communications traffic [Organization-defined: organization-defined frequency] for [Organization-defined: organization-defined unusual or unauthorized activities or conditions].
Official discussion

Unusual or unauthorized activities or conditions related to system inbound and outbound communications traffic includes internal traffic that indicates the presence of malicious code or unauthorized use of legitimate code or credentials within organizational systems or propagating among system components, signaling to external systems, and the unauthorized exporting of information. Evidence of malicious code or unauthorized use of legitimate code or credentials is used to identify potentially compromised systems or system components.

Organization-defined parameters (6)
organization-defined frequency
organization-defined unusual or unauthorized activities or conditions
frequencythe frequency at which to monitor inbound communications traffic for unusual or unauthorized activities or conditions is defined;
unusual or unauthorized activities or conditionsunusual or unauthorized activities or conditions that are to be monitored in inbound communications traffic are defined;
frequencythe frequency at which to monitor outbound communications traffic for unusual or unauthorized activities or conditions is defined;
unusual or unauthorized activities or conditionsunusual or unauthorized activities or conditions that are to be monitored in outbound communications traffic are defined;
Assessment objectives and methods
  1. SI-04(04)(a)
    1. SI-04(04)(a)[01]criteria for unusual or unauthorized activities or conditions for inbound communications traffic are defined;
    2. SI-04(04)(a)[02]criteria for unusual or unauthorized activities or conditions for outbound communications traffic are defined;
  2. SI-04(04)(b)
    1. SI-04(04)(b)[01]inbound communications traffic is monitored [Organization-defined: frequency] for [Organization-defined: unusual or unauthorized activities or conditions];
    2. SI-04(04)(b)[02]outbound communications traffic is monitored [Organization-defined: frequency] for [Organization-defined: unusual or unauthorized activities or conditions].

Examine

  • System and information integrity policy
  • system and information integrity procedures
  • procedures addressing system monitoring tools and techniques
  • system design documentation
  • system monitoring tools and techniques documentation
  • system configuration settings and associated documentation
  • system protocols
  • system audit records
  • system security plan
  • other relevant documents or records

Interview

  • System/network administrators
  • organizational personnel with information security responsibilities
  • organizational personnel installing, configuring, and/or maintaining the system
  • organizational personnel responsible for monitoring the system
  • organizational personnel responsible for the intrusion detection system

Test

  • Organizational processes for intrusion detection and system monitoring
  • mechanisms supporting and/or implementing intrusion detection and system monitoring capabilities
  • mechanisms supporting and/or implementing the monitoring of inbound and outbound communications traffic
Official NIST control enhancement

SI-4(5) — System-generated Alerts

ModerateHigh

Alert [Organization-defined: personnel or roles] when the following system-generated indications of compromise or potential compromise occur: [Organization-defined: compromise indicators].

Official discussion

Alerts may be generated from a variety of sources, including audit records or inputs from malicious code protection mechanisms, intrusion detection or prevention mechanisms, or boundary protection devices such as firewalls, gateways, and routers. Alerts can be automated and may be transmitted telephonically, by electronic mail messages, or by text messaging. Organizational personnel on the alert notification list can include system administrators, mission or business owners, system owners, information owners/stewards, senior agency information security officers, senior agency officials for privacy, system security officers, or privacy officers. In contrast to alerts generated by the system, alerts generated by organizations in [SI-4(12)](#si-4.12) focus on information sources external to the system, such as suspicious activity reports and reports on potential insider threats.

Organization-defined parameters (2)
personnel or rolespersonnel or roles to be alerted when indications of compromise or potential compromise occur is/are defined;
compromise indicatorscompromise indicators are defined;
Assessment objectives and methods

[Organization-defined: personnel or roles] are alerted when system-generated [Organization-defined: compromise indicators] occur.

Examine

  • System and information integrity policy
  • system and information integrity procedures
  • procedures addressing system monitoring tools and techniques
  • system monitoring tools and techniques documentation
  • system configuration settings and associated documentation
  • list of personnel selected to receive alerts
  • documentation of alerts generated based on compromise indicators
  • system audit records
  • system security plan
  • privacy plan
  • other relevant documents or records

Interview

  • System/network administrators
  • organizational personnel with information security and privacy responsibilities
  • system developers
  • organizational personnel installing, configuring, and/or maintaining the system
  • organizational personnel responsible for monitoring the system
  • organizational personnel on the system alert notification list
  • organizational personnel responsible for the intrusion detection system

Test

  • Organizational processes for intrusion detection and system monitoring
  • mechanisms supporting and/or implementing intrusion detection and system monitoring capabilities
  • mechanisms supporting and/or implementing alerts for compromise indicators
Related controls
Official NIST control enhancement

SI-4(6) — Restrict Non-privileged Users

Withdrawn

This enhancement is marked withdrawn in the official OSCAL catalog. Related-control metadata below may identify where its intent was incorporated.

Official NIST control enhancement

SI-4(7) — Automated Response to Suspicious Events

  1. (a)Notify [Organization-defined: incident response personnel] of detected suspicious events; and
  2. (b)Take the following actions upon detection: [Organization-defined: least-disruptive actions].
Official discussion

Least-disruptive actions include initiating requests for human responses.

Organization-defined parameters (2)
incident response personnelincident response personnel (identified by name and/or by role) to be notified of detected suspicious events is/are defined;
least-disruptive actionsleast-disruptive actions to terminate suspicious events are defined;
Assessment objectives and methods
  1. SI-04(07)(a)[Organization-defined: incident response personnel] are notified of detected suspicious events;
  2. SI-04(07)(b)[Organization-defined: least-disruptive actions] are taken upon the detection of suspicious events.

Examine

  • System and information integrity policy
  • system and information integrity procedures
  • procedures addressing system monitoring tools and techniques
  • system design documentation
  • system monitoring tools and techniques documentation
  • system configuration settings and associated documentation
  • alerts and notifications generated based on detected suspicious events
  • records of actions taken to terminate suspicious events
  • system audit records
  • system security plan
  • other relevant documents or records

Interview

  • System/network administrators
  • organizational personnel with information security responsibilities
  • system developers
  • organizational personnel installing, configuring, and/or maintaining the system
  • organizational personnel responsible for monitoring the system
  • organizational personnel responsible for the intrusion detection system

Test

  • Organizational processes for intrusion detection and system monitoring
  • mechanisms supporting and/or implementing intrusion detection and system monitoring capabilities
  • mechanisms supporting and/or implementing notifications to incident response personnel
  • mechanisms supporting and/or implementing actions to terminate suspicious events
Official NIST control enhancement

SI-4(8) — Protection of Monitoring Information

Withdrawn

This enhancement is marked withdrawn in the official OSCAL catalog. Related-control metadata below may identify where its intent was incorporated.

Official NIST control enhancement

SI-4(9) — Testing of Monitoring Tools and Mechanisms

Test intrusion-monitoring tools and mechanisms [Organization-defined: frequency].

Official discussion

Testing intrusion-monitoring tools and mechanisms is necessary to ensure that the tools and mechanisms are operating correctly and continue to satisfy the monitoring objectives of organizations. The frequency and depth of testing depends on the types of tools and mechanisms used by organizations and the methods of deployment.

Organization-defined parameters (1)
frequencya frequency at which to test intrusion-monitoring tools and mechanisms is defined;
Assessment objectives and methods

intrusion-monitoring tools and mechanisms are tested [Organization-defined: frequency].

Examine

  • System and information integrity policy
  • system and information integrity procedures
  • procedures addressing the testing of system monitoring tools and techniques
  • documentation providing evidence of testing intrusion-monitoring tools
  • system security plan
  • other relevant documents or records

Interview

  • System/network administrators
  • organizational personnel with information security responsibilities
  • organizational personnel installing, configuring, and/or maintaining the system
  • organizational personnel responsible for monitoring the system
  • organizational personnel responsible for the intrusion detection system

Test

  • Organizational processes for intrusion detection and system monitoring
  • mechanisms supporting and/or implementing intrusion detection and system monitoring capabilities
  • mechanisms supporting and/or implementing the testing of intrusion-monitoring tools
Official NIST control enhancement

SI-4(10) — Visibility of Encrypted Communications

High

Make provisions so that [Organization-defined: encrypted communications traffic] is visible to [Organization-defined: system monitoring tools and mechanisms].

Official discussion

Organizations balance the need to encrypt communications traffic to protect data confidentiality with the need to maintain visibility into such traffic from a monitoring perspective. Organizations determine whether the visibility requirement applies to internal encrypted traffic, encrypted traffic intended for external destinations, or a subset of the traffic types.

Organization-defined parameters (2)
encrypted communications trafficencrypted communications traffic to be made visible to system monitoring tools and mechanisms is defined;
system monitoring tools and mechanismssystem monitoring tools and mechanisms to be provided access to encrypted communications traffic are defined;
Assessment objectives and methods

provisions are made so that [Organization-defined: encrypted communications traffic] is visible to [Organization-defined: system monitoring tools and mechanisms].

Examine

  • System and information integrity policy
  • system and information integrity procedures
  • procedures addressing system monitoring tools and techniques
  • system design documentation
  • system monitoring tools and techniques documentation
  • system configuration settings and associated documentation
  • system protocols
  • system security plan
  • other relevant documents or records

Interview

  • System/network administrators
  • organizational personnel with information security responsibilities
  • organizational personnel installing, configuring, and/or maintaining the system
  • organizational personnel responsible for monitoring the system
  • organizational personnel responsible for the intrusion detection system

Test

  • Organizational processes for intrusion detection and system monitoring
  • mechanisms supporting and/or implementing intrusion detection and system monitoring capabilities
  • mechanisms supporting and/or implementing the visibility of encrypted communications traffic to monitoring tools
Official NIST control enhancement

SI-4(11) — Analyze Communications Traffic Anomalies

Analyze outbound communications traffic at the external interfaces to the system and selected [Organization-defined: interior points] to discover anomalies.

Official discussion

Organization-defined interior points include subnetworks and subsystems. Anomalies within organizational systems include large file transfers, long-time persistent connections, attempts to access information from unexpected locations, the use of unusual protocols and ports, the use of unmonitored network protocols (e.g., IPv6 usage during IPv4 transition), and attempted communications with suspected malicious external addresses.

Organization-defined parameters (1)
interior pointsinterior points within the system where communications traffic is to be analyzed are defined;
Assessment objectives and methods
  1. SI-04(11)[01]outbound communications traffic at the external interfaces to the system is analyzed to discover anomalies;
  2. SI-04(11)[02]outbound communications traffic at [Organization-defined: interior points] is analyzed to discover anomalies.

Examine

  • System and information integrity policy
  • system and information integrity procedures
  • procedures addressing system monitoring tools and techniques
  • system design documentation
  • network diagram
  • system monitoring tools and techniques documentation
  • system configuration settings and associated documentation
  • system monitoring logs or records
  • system audit records
  • system security plan
  • other relevant documents or records

Interview

  • System/network administrators
  • organizational personnel with information security responsibilities
  • organizational personnel installing, configuring, and/or maintaining the system
  • organizational personnel responsible for monitoring the system
  • organizational personnel responsible for the intrusion detection system

Test

  • Organizational processes for intrusion detection and system monitoring
  • mechanisms supporting and/or implementing intrusion detection and system monitoring capabilities
  • mechanisms supporting and/or implementing the analysis of communications traffic
Official NIST control enhancement

SI-4(12) — Automated Organization-generated Alerts

High

Alert [Organization-defined: personnel or roles] using [Organization-defined: automated mechanisms] when the following indications of inappropriate or unusual activities with security or privacy implications occur: [Organization-defined: activities that trigger alerts].

Official discussion

Organizational personnel on the system alert notification list include system administrators, mission or business owners, system owners, senior agency information security officer, senior agency official for privacy, system security officers, or privacy officers. Automated organization-generated alerts are the security alerts generated by organizations and transmitted using automated means. The sources for organization-generated alerts are focused on other entities such as suspicious activity reports and reports on potential insider threats. In contrast to alerts generated by the organization, alerts generated by the system in [SI-4(5)](#si-4.5) focus on information sources that are internal to the systems, such as audit records.

Organization-defined parameters (3)
personnel or rolespersonnel or roles to be alerted when indications of inappropriate or unusual activity with security or privacy implications occur is/are defined;
automated mechanismsautomated mechanisms used to alert personnel or roles are defined;
activities that trigger alertsactivities that trigger alerts to personnel or are defined;
Assessment objectives and methods

[Organization-defined: personnel or roles] is/are alerted using [Organization-defined: automated mechanisms] when [Organization-defined: activities that trigger alerts] indicate inappropriate or unusual activities with security or privacy implications.

Examine

  • System and information integrity policy
  • system and information integrity procedures
  • procedures addressing system monitoring tools and techniques
  • system design documentation
  • system monitoring tools and techniques documentation
  • system configuration settings and associated documentation
  • list of inappropriate or unusual activities with security and privacy implications that trigger alerts
  • suspicious activity reports
  • alerts provided to security and privacy personnel
  • system monitoring logs or records
  • system audit records
  • system security plan
  • privacy plan
  • other relevant documents or records

Interview

  • System/network administrators
  • organizational personnel with information security and privacy responsibilities
  • system developers
  • organizational personnel installing, configuring, and/or maintaining the system
  • organizational personnel responsible for monitoring the system
  • organizational personnel responsible for the intrusion detection system

Test

  • Organizational processes for intrusion detection and system monitoring
  • automated mechanisms supporting and/or implementing intrusion detection and system monitoring capabilities
  • automated mechanisms supporting and/or implementing automated alerts to security personnel
Official NIST control enhancement

SI-4(13) — Analyze Traffic and Event Patterns

  1. (a)Analyze communications traffic and event patterns for the system;
  2. (b)Develop profiles representing common traffic and event patterns; and
  3. (c)Use the traffic and event profiles in tuning system-monitoring devices.
Official discussion

Identifying and understanding common communications traffic and event patterns help organizations provide useful information to system monitoring devices to more effectively identify suspicious or anomalous traffic and events when they occur. Such information can help reduce the number of false positives and false negatives during system monitoring.

Assessment objectives and methods
  1. SI-04(13)(a)
    1. SI-04(13)(a)[01]communications traffic for the system is analyzed;
    2. SI-04(13)(a)[02]event patterns for the system are analyzed;
  2. SI-04(13)(b)
    1. SI-04(13)(b)[01]profiles representing common traffic are developed;
    2. SI-04(13)(b)[02]profiles representing event patterns are developed;
  3. SI-04(13)(c)
    1. SI-04(13)(c)[01]traffic profiles are used in tuning system-monitoring devices;
    2. SI-04(13)(c)[02]event profiles are used in tuning system-monitoring devices.

Examine

  • System and information integrity policy
  • system and information integrity procedures
  • procedures addressing system monitoring tools and techniques
  • system design documentation
  • system monitoring tools and techniques documentation
  • system configuration settings and associated documentation
  • list of profiles representing common traffic patterns and/or events
  • system protocols documentation
  • list of acceptable thresholds for false positives and false negatives
  • system security plan
  • other relevant documents or records

Interview

  • System/network administrators
  • organizational personnel with information security responsibilities
  • organizational personnel installing, configuring, and/or maintaining the system
  • organizational personnel responsible for monitoring the system
  • organizational personnel responsible for the intrusion detection system

Test

  • Organizational processes for intrusion detection and system monitoring
  • mechanisms supporting and/or implementing intrusion detection and system monitoring capabilities
  • mechanisms supporting and/or implementing the analysis of communications traffic and event patterns
Official NIST control enhancement

SI-4(14) — Wireless Intrusion Detection

High

Employ a wireless intrusion detection system to identify rogue wireless devices and to detect attack attempts and potential compromises or breaches to the system.

Official discussion

Wireless signals may radiate beyond organizational facilities. Organizations proactively search for unauthorized wireless connections, including the conduct of thorough scans for unauthorized wireless access points. Wireless scans are not limited to those areas within facilities containing systems but also include areas outside of facilities to verify that unauthorized wireless access points are not connected to organizational systems.

Assessment objectives and methods
  1. SI-04(14)[01]a wireless intrusion detection system is employed to identify rogue wireless devices;
  2. SI-04(14)[02]a wireless intrusion detection system is employed to detect attack attempts on the system;
  3. SI-04(14)[03]a wireless intrusion detection system is employed to detect potential compromises or breaches to the system.

Examine

  • System and information integrity policy
  • system and information integrity procedures
  • procedures addressing system monitoring tools and techniques
  • system design documentation
  • system monitoring tools and techniques documentation
  • system configuration settings and associated documentation
  • system protocols
  • system audit records
  • system security plan
  • other relevant documents or records

Interview

  • System/network administrators
  • organizational personnel with information security responsibilities
  • organizational personnel installing, configuring, and/or maintaining the system
  • organizational personnel responsible for monitoring the system
  • organizational personnel responsible for the intrusion detection system

Test

  • Organizational processes for intrusion detection
  • mechanisms supporting and/or implementing a wireless intrusion detection capability
Related controls
Official NIST control enhancement

SI-4(15) — Wireless to Wireline Communications

Employ an intrusion detection system to monitor wireless communications traffic as the traffic passes from wireless to wireline networks.

Official discussion

Wireless networks are inherently less secure than wired networks. For example, wireless networks are more susceptible to eavesdroppers or traffic analysis than wireline networks. When wireless to wireline communications exist, the wireless network could become a port of entry into the wired network. Given the greater facility of unauthorized network access via wireless access points compared to unauthorized wired network access from within the physical boundaries of the system, additional monitoring of transitioning traffic between wireless and wired networks may be necessary to detect malicious activities. Employing intrusion detection systems to monitor wireless communications traffic helps to ensure that the traffic does not contain malicious code prior to transitioning to the wireline network.

Assessment objectives and methods

an intrusion detection system is employed to monitor wireless communications traffic as the traffic passes from wireless to wireline networks.

Examine

  • System and information integrity policy
  • system and information integrity procedures
  • procedures addressing system monitoring tools and techniques
  • system design documentation
  • system monitoring tools and techniques documentation
  • system configuration settings and associated documentation
  • system protocols documentation
  • system audit records
  • system security plan
  • other relevant documents or records

Interview

  • System/network administrators
  • organizational personnel with information security responsibilities
  • organizational personnel installing, configuring, and/or maintaining the system
  • organizational personnel responsible for monitoring the system
  • organizational personnel responsible for the intrusion detection system

Test

  • Organizational processes for intrusion detection and system monitoring
  • mechanisms supporting and/or implementing intrusion detection and system monitoring capabilities
  • mechanisms supporting and/or implementing a wireless intrusion detection capability
Related controls
Official NIST control enhancement

SI-4(16) — Correlate Monitoring Information

Correlate information from monitoring tools and mechanisms employed throughout the system.

Official discussion

Correlating information from different system monitoring tools and mechanisms can provide a more comprehensive view of system activity. Correlating system monitoring tools and mechanisms that typically work in isolation—including malicious code protection software, host monitoring, and network monitoring—can provide an organization-wide monitoring view and may reveal otherwise unseen attack patterns. Understanding the capabilities and limitations of diverse monitoring tools and mechanisms and how to maximize the use of information generated by those tools and mechanisms can help organizations develop, operate, and maintain effective monitoring programs. The correlation of monitoring information is especially important during the transition from older to newer technologies (e.g., transitioning from IPv4 to IPv6 network protocols).

Assessment objectives and methods

information from monitoring tools and mechanisms employed throughout the system is correlated.

Examine

  • System and information integrity policy
  • system and information integrity procedures
  • procedures addressing system monitoring tools and techniques
  • system design documentation
  • system monitoring tools and techniques documentation
  • system configuration settings and associated documentation
  • event correlation logs or records
  • system audit records
  • system security plan
  • other relevant documents or records

Interview

  • System/network administrators
  • organizational personnel with information security responsibilities
  • organizational personnel installing, configuring, and/or maintaining the system
  • organizational personnel responsible for monitoring the system
  • organizational personnel responsible for the intrusion detection system

Test

  • Organizational processes for intrusion detection and system monitoring
  • mechanisms supporting and/or implementing intrusion detection and system monitoring capabilities
  • mechanisms supporting and/or implementing the correlation of information from monitoring tools
Related controls
Official NIST control enhancement

SI-4(17) — Integrated Situational Awareness

Correlate information from monitoring physical, cyber, and supply chain activities to achieve integrated, organization-wide situational awareness.

Official discussion

Correlating monitoring information from a more diverse set of information sources helps to achieve integrated situational awareness. Integrated situational awareness from a combination of physical, cyber, and supply chain monitoring activities enhances the capability of organizations to more quickly detect sophisticated attacks and investigate the methods and techniques employed to carry out such attacks. In contrast to [SI-4(16)](#si-4.16) , which correlates the various cyber monitoring information, integrated situational awareness is intended to correlate monitoring beyond the cyber domain. Correlation of monitoring information from multiple activities may help reveal attacks on organizations that are operating across multiple attack vectors.

Assessment objectives and methods

information from monitoring physical, cyber, and supply chain activities are correlated to achieve integrated, organization-wide situational awareness.

Examine

  • System and information integrity policy
  • system and information integrity procedures
  • procedures addressing system monitoring tools and techniques
  • system design documentation
  • system monitoring tools and techniques documentation
  • system configuration settings and associated documentation
  • event correlation logs or records resulting from physical, cyber, and supply chain activities
  • system audit records
  • system security plan
  • supply chain risk management plan
  • other relevant documents or records

Interview

  • System/network administrators
  • organizational personnel with information security responsibilities
  • organizational personnel installing, configuring, and/or maintaining the system
  • organizational personnel responsible for monitoring the system
  • organizational personnel responsible for the intrusion detection system

Test

  • Organizational processes for intrusion detection and system monitoring
  • mechanisms supporting and/or implementing intrusion detection and system monitoring capabilities
  • mechanisms supporting and/or implementing the correlation of information from monitoring tools
Related controls
Official NIST control enhancement

SI-4(18) — Analyze Traffic and Covert Exfiltration

Analyze outbound communications traffic at external interfaces to the system and at the following interior points to detect covert exfiltration of information: [Organization-defined: interior points].

Official discussion

Organization-defined interior points include subnetworks and subsystems. Covert means that can be used to exfiltrate information include steganography.

Organization-defined parameters (1)
interior pointsinterior points within the system where communications traffic is to be analyzed are defined;
Assessment objectives and methods
  1. SI-04(18)[01]outbound communications traffic is analyzed at interfaces external to the system to detect covert exfiltration of information;
  2. SI-04(18)[02]outbound communications traffic is analyzed at [Organization-defined: interior points] to detect covert exfiltration of information.

Examine

  • System and information integrity policy
  • system and information integrity procedures
  • procedures addressing system monitoring tools and techniques
  • system design documentation
  • network diagram
  • system monitoring tools and techniques documentation
  • system configuration settings and associated documentation
  • system monitoring logs or records
  • system audit records
  • system security plan
  • other relevant documents or records

Interview

  • System/network administrators
  • organizational personnel with information security responsibilities
  • organizational personnel installing, configuring, and/or maintaining the system
  • organizational personnel responsible for monitoring the system
  • organizational personnel responsible for the intrusion detection system

Test

  • Organizational processes for intrusion detection and system monitoring
  • mechanisms supporting and/or implementing intrusion detection and system monitoring capabilities
  • mechanisms supporting and/or implementing an analysis of outbound communications traffic
Official NIST control enhancement

SI-4(19) — Risk for Individuals

Implement [Organization-defined: additional monitoring] of individuals who have been identified by [Organization-defined: sources] as posing an increased level of risk.

Official discussion

Indications of increased risk from individuals can be obtained from different sources, including personnel records, intelligence agencies, law enforcement organizations, and other sources. The monitoring of individuals is coordinated with the management, legal, security, privacy, and human resource officials who conduct such monitoring. Monitoring is conducted in accordance with applicable laws, executive orders, directives, regulations, policies, standards, and guidelines.

Organization-defined parameters (2)
additional monitoringadditional monitoring of individuals who have been identified as posing an increased level of risk is defined;
sourcessources that identify individuals who pose an increased level of risk are defined;
Assessment objectives and methods

[Organization-defined: additional monitoring] is implemented on individuals who have been identified by [Organization-defined: sources] as posing an increased level of risk.

Examine

  • System and information integrity policy
  • system and information integrity procedures
  • procedures addressing system monitoring
  • system design documentation
  • system monitoring tools and techniques documentation
  • system configuration settings and associated documentation
  • system audit records
  • system security plan
  • privacy plan
  • other relevant documents or records

Interview

  • System/network administrators
  • organizational personnel with information security and privacy responsibilities
  • organizational personnel installing, configuring, and/or maintaining the system
  • organizational personnel responsible for monitoring the system
  • legal counsel
  • human resource officials
  • organizational personnel with personnel security responsibilities

Test

  • Organizational processes for system monitoring
  • mechanisms supporting and/or implementing a system monitoring capability
Official NIST control enhancement

SI-4(20) — Privileged Users

High

Implement the following additional monitoring of privileged users: [Organization-defined: additional monitoring].

Official discussion

Privileged users have access to more sensitive information, including security-related information, than the general user population. Access to such information means that privileged users can potentially do greater damage to systems and organizations than non-privileged users. Therefore, implementing additional monitoring on privileged users helps to ensure that organizations can identify malicious activity at the earliest possible time and take appropriate actions.

Organization-defined parameters (1)
additional monitoringadditional monitoring of privileged users is defined;
Assessment objectives and methods

[Organization-defined: additional monitoring] of privileged users is implemented.

Examine

  • System and information integrity policy
  • system and information integrity procedures
  • procedures addressing system monitoring tools and techniques
  • system design documentation
  • system monitoring tools and techniques documentation
  • system configuration settings and associated documentation
  • system monitoring logs or records
  • system audit records
  • system security plan
  • other relevant documents or records

Interview

  • System/network administrators
  • organizational personnel with information security responsibilities
  • organizational personnel installing, configuring, and/or maintaining the system
  • organizational personnel responsible for monitoring the system

Test

  • Organizational processes for system monitoring
  • mechanisms supporting and/or implementing a system monitoring capability
Related controls
Official NIST control enhancement

SI-4(21) — Probationary Periods

Implement the following additional monitoring of individuals during [Organization-defined: probationary period]: [Organization-defined: additional monitoring].

Official discussion

During probationary periods, employees do not have permanent employment status within organizations. Without such status or access to information that is resident on the system, additional monitoring can help identify any potentially malicious activity or inappropriate behavior.

Organization-defined parameters (2)
additional monitoringadditional monitoring to be implemented on individuals during probationary periods is defined;
probationary periodthe probationary period of individuals is defined;
Assessment objectives and methods

[Organization-defined: additional monitoring] of individuals is implemented during [Organization-defined: probationary period].

Examine

  • System and information integrity policy
  • system and information integrity procedures
  • procedures addressing system monitoring
  • system design documentation
  • system monitoring tools and techniques documentation
  • system configuration settings and associated documentation
  • system monitoring logs or records
  • system audit records
  • system security plan
  • other relevant documents or records

Interview

  • System/network administrators
  • organizational personnel with information security responsibilities
  • organizational personnel installing, configuring, and/or maintaining the system
  • organizational personnel responsible for monitoring the system

Test

  • Organizational processes for system monitoring
  • mechanisms supporting and/or implementing a system monitoring capability
Related controls
Official NIST control enhancement

SI-4(22) — Unauthorized Network Services

High
  1. (a)Detect network services that have not been authorized or approved by [Organization-defined: authorization or approval processes] ; and
  2. (b)[Organization-defined: si-04.22_odp.02] when detected.
Official discussion

Unauthorized or unapproved network services include services in service-oriented architectures that lack organizational verification or validation and may therefore be unreliable or serve as malicious rogues for valid services.

Organization-defined parameters (3)
authorization or approval processesauthorization or approval processes for network services are defined;
si-04.22_odp.02
personnel or rolespersonnel or roles to be alerted upon the detection of network services that have not been authorized or approved by authorization or approval processes is/are defined (if selected);
Assessment objectives and methods
  1. SI-04(22)(a)network services that have not been authorized or approved by [Organization-defined: authorization or approval processes] are detected;
  2. SI-04(22)(b)[Organization-defined: si-04.22_odp.02] is/are initiated when network services that have not been authorized or approved by authorization or approval processes are detected.

Examine

  • System and information integrity policy
  • system and information integrity procedures
  • procedures addressing system monitoring tools and techniques
  • system design documentation
  • system monitoring tools and techniques documentation
  • system configuration settings and associated documentation
  • documented authorization/approval of network services
  • notifications or alerts of unauthorized network services
  • system monitoring logs or records
  • system audit records
  • system security plan
  • other relevant documents or records

Interview

  • System/network administrators
  • organizational personnel with information security responsibilities
  • system developer
  • organizational personnel installing, configuring, and/or maintaining the system
  • organizational personnel responsible for monitoring the system

Test

  • Organizational processes for system monitoring
  • mechanisms supporting and/or implementing a system monitoring capability
  • mechanisms for auditing network services
  • mechanisms for providing alerts
Related controls
Official NIST control enhancement

SI-4(23) — Host-based Devices

Implement the following host-based monitoring mechanisms at [Organization-defined: system components]: [Organization-defined: host-based monitoring mechanisms].

Official discussion

Host-based monitoring collects information about the host (or system in which it resides). System components in which host-based monitoring can be implemented include servers, notebook computers, and mobile devices. Organizations may consider employing host-based monitoring mechanisms from multiple product developers or vendors.

Organization-defined parameters (2)
host-based monitoring mechanismshost-based monitoring mechanisms to be implemented on system components are defined;
system componentssystem components where host-based monitoring is to be implemented are defined;
Assessment objectives and methods

[Organization-defined: host-based monitoring mechanisms] are implemented on [Organization-defined: system components].

Examine

  • System and information integrity policy
  • system and information integrity procedures
  • procedures addressing system monitoring tools and techniques
  • system design documentation
  • host-based monitoring mechanisms
  • system monitoring tools and techniques documentation
  • system configuration settings and associated documentation
  • list of system components requiring host-based monitoring
  • system monitoring logs or records
  • system audit records
  • system security plan
  • other relevant documents or records

Interview

  • System/network administrators
  • organizational personnel with information security responsibilities
  • organizational personnel installing, configuring, and/or maintaining the system
  • organizational personnel responsible for monitoring system hosts

Test

  • Organizational processes for system monitoring
  • mechanisms supporting and/or implementing a host-based monitoring capability
Related controls
Official NIST control enhancement

SI-4(24) — Indicators of Compromise

Discover, collect, and distribute to [Organization-defined: personnel or roles] , indicators of compromise provided by [Organization-defined: sources].

Official discussion

Indicators of compromise (IOC) are forensic artifacts from intrusions that are identified on organizational systems at the host or network level. IOCs provide valuable information on systems that have been compromised. IOCs can include the creation of registry key values. IOCs for network traffic include Universal Resource Locator or protocol elements that indicate malicious code command and control servers. The rapid distribution and adoption of IOCs can improve information security by reducing the time that systems and organizations are vulnerable to the same exploit or attack. Threat indicators, signatures, tactics, techniques, procedures, and other indicators of compromise may be available via government and non-government cooperatives, including the Forum of Incident Response and Security Teams, the United States Computer Emergency Readiness Team, the Defense Industrial Base Cybersecurity Information Sharing Program, and the CERT Coordination Center.

Organization-defined parameters (2)
sourcessources that provide indicators of compromise are defined;
personnel or rolespersonnel or roles to whom indicators of compromise are to be distributed is/are defined;
Assessment objectives and methods
  1. SI-04(24)[01]indicators of compromise provided by [Organization-defined: sources] are discovered;
  2. SI-04(24)[02]indicators of compromise provided by [Organization-defined: sources] are collected;
  3. SI-04(24)[03]indicators of compromise provided by [Organization-defined: sources] are distributed to [Organization-defined: personnel or roles].

Examine

  • System and information integrity policy
  • system and information integrity procedures
  • procedures addressing system monitoring
  • system design documentation
  • system monitoring tools and techniques documentation
  • system configuration settings and associated documentation
  • system monitoring logs or records
  • system audit records
  • system security plan
  • other relevant documents or records

Interview

  • System/network administrators
  • organizational personnel with information security responsibilities
  • system developer
  • organizational personnel installing, configuring, and/or maintaining the system
  • organizational personnel responsible for monitoring system hosts

Test

  • Organizational processes for system monitoring
  • organizational processes for the discovery, collection, distribution, and use of indicators of compromise
  • mechanisms supporting and/or implementing a system monitoring capability
  • mechanisms supporting and/or implementing the discovery, collection, distribution, and use of indicators of compromise
Related controls
Official NIST control enhancement

SI-4(25) — Optimize Network Traffic Analysis

Provide visibility into network traffic at external and key internal system interfaces to optimize the effectiveness of monitoring devices.

Official discussion

Encrypted traffic, asymmetric routing architectures, capacity and latency limitations, and transitioning from older to newer technologies (e.g., IPv4 to IPv6 network protocol transition) may result in blind spots for organizations when analyzing network traffic. Collecting, decrypting, pre-processing, and distributing only relevant traffic to monitoring devices can streamline the efficiency and use of devices and optimize traffic analysis.

Assessment objectives and methods
  1. SI-04(25)[01]visibility into network traffic at external system interfaces is provided to optimize the effectiveness of monitoring devices;
  2. SI-04(25)[02]visibility into network traffic at key internal system interfaces is provided to optimize the effectiveness of monitoring devices.

Examine

  • System and information integrity policy
  • system and information integrity procedures
  • procedures addressing system monitoring
  • system design documentation
  • system monitoring tools and techniques documentation
  • system configuration settings and associated documentation
  • system monitoring logs or records
  • system architecture
  • system audit records
  • network traffic reports
  • system security plan
  • other relevant documents or records

Interview

  • System/network administrators
  • organizational personnel with information security responsibilities
  • system developer
  • organizational personnel installing, configuring, and/or maintaining the system
  • organizational personnel responsible for monitoring system hosts

Test

  • Organizational processes for system monitoring
  • organizational processes for the discovery, collection, distribution, and use of indicators of compromise
  • mechanisms supporting and/or implementing a system monitoring capability
  • mechanisms supporting and/or implementing the discovery, collection, distribution, and use of indicators of compromise
Source record

Authoritative sources