NIST800-SI-4 SI-4 System Monitoring
NIST800-SI-4 in NIST SP 800-53 Rev 5 (NIST SP 800-53 Rev 5, Release 5.2.0). All NIST SP 800-53 Rev 5 controls held. Open NIST SP 800-53 Rev 5 on the standards site.
The control as we hold it
SI-4 System Monitoring. a. Monitor the system to detect: 1. Attacks and indicators of potential attacks in accordance with the following monitoring objectives: [Assignment: organization-defined monitoring objectives]; and 2. Unauthorized local, network, and remote connections; b. Identify unauthorized use of the system through the following techniques and methods: [Assignment: organization-defined techniques and methods]; c. Invoke internal monitoring capabilities or deploy monitoring devices: 1. Strategically within the system to collect organization-determined essential information; and 2. At ad hoc locations within the system to track specific types of transactions of interest to the.
Reviewed and closest counterparts in the other frameworks
Reviewed rows come from a released pair; a closest match is the nearest held text and is not a reviewed row.
SOC 2
- SOC2-CC4.1 CC4.1 Ongoing and separate evaluations of control (COSO principle 16) (closest match)
- SOC2-CC6.6 CC6.6 Protection against threats from outside the system boundary (closest match)
- SOC2-CC7.1 CC7.1 Detecting configuration changes and new vulnerabilities (closest match)
- SOC2-CC7.2 CC7.2 Monitoring system components for anomalies (closest match)
- SOC2-CC7.3 CC7.3 Evaluating security events to identify incidents (closest match)
HIPAA Security Rule
- 164.308(a)(1)(ii)(D) Information System Activity Review (Required) (closest match)
- 164.308(a)(5)(ii)(C) Log-in Monitoring (Addressable) (closest match)
What an auditor commonly asks for
General guidance for this control area (domain: SI - System and Information Integrity), in our words, not a statement of the standard and not binding on an assessor.
- the integrity policy
- the flaw-remediation and malware records
- the monitoring records