id: "SI-04" title: "System Monitoring" family: "SI" family_name: "System and Information Integrity" sort_id: "si-04" priority: "P1" implementation_level: "system" enhancements: - si-4.1 - si-4.2 - si-4.3 - si-4.4 - si-4.5 - si-4.6 - si-4.7 - si-4.8 - si-4.9 - si-4.10 - si-4.11 - si-4.12 - si-4.13 - si-4.14 - si-4.15 - si-4.16 - si-4.17 - si-4.18 - si-4.19 - si-4.20 - si-4.21 - si-4.22 - si-4.23 - si-4.24 - si-4.25


Monitor the system to detect:

Attacks and indicators of potential attacks in accordance with the following monitoring objectives: {{ insert: param, si-04_odp.01 }} ; and

Unauthorized local, network, and remote connections;

Identify unauthorized use of the system through the following techniques and methods: {{ insert: param, si-04_odp.02 }};

Invoke internal monitoring capabilities or deploy monitoring devices:

Strategically within the system to collect organization-determined essential information; and

At ad hoc locations within the system to track specific types of transactions of interest to the organization;

Analyze detected events and anomalies;

Adjust the level of system monitoring activity when there is a change in risk to organizational operations and assets, individuals, other organizations, or the Nation;

Obtain legal opinion regarding system monitoring activities; and

Provide {{ insert: param, si-04_odp.03 }} to {{ insert: param, si-04_odp.04 }} {{ insert: param, si-04_odp.05 }}.

Guidance

System monitoring includes external and internal monitoring. External monitoring includes the observation of events occurring at external interfaces to the system. Internal monitoring includes the observation of events occurring within the system. Organizations monitor systems by observing audit activities in real time or by observing other system aspects such as access patterns, characteristics of access, and other actions. The monitoring objectives guide and inform the determination of the events. System monitoring capabilities are achieved through a variety of tools and techniques, including intrusion detection and prevention systems, malicious code protection software, scanning tools, audit record monitoring software, and network monitoring software.

Depending on the security architecture, the distribution and configuration of monitoring devices may impact throughput at key internal and external boundaries as well as at other locations across a network due to the introduction of network throughput latency. If throughput management is needed, such devices are strategically located and deployed as part of an established organization-wide security architecture. Strategic locations for monitoring devices include selected perimeter locations and near key servers and server farms that support critical applications. Monitoring devices are typically employed at the managed interfaces associated with controls SC-7 and AC-17 . The information collected is a function of the organizational monitoring objectives and the capability of systems to support such objectives. Specific types of transactions of interest include Hypertext Transfer Protocol (HTTP) traffic that bypasses HTTP proxies. System monitoring is an integral part of organizational continuous monitoring and incident response programs, and output from system monitoring serves as input to those programs. System monitoring requirements, including the need for specific types of system monitoring, may be referenced in other controls (e.g., AC-2g, AC-2(7), AC-2(12)(a), AC-17(1), AU-13, AU-13(1), AU-13(2), CM-3f, CM-6d, MA-3a, MA-4a, SC-5(3)(b), SC-7a, SC-7(24)(b), SC-18b, SC-43b ). Adjustments to levels of system monitoring are based on law enforcement information, intelligence information, or other sources of information. The legality of system monitoring activities is based on applicable laws, executive orders, directives, regulations, policies, standards, and guidelines.

Assessment Objective: the system is monitored to detect attacks and indicators of potential attacks in accordance with {{ insert: param, si-04_odp.01 }};

Assessment Objective: the system is monitored to detect unauthorized local connections;

Assessment Objective: the system is monitored to detect unauthorized network connections;

Assessment Objective: the system is monitored to detect unauthorized remote connections;

Assessment Objective: unauthorized use of the system is identified through {{ insert: param, si-04_odp.02 }};

Assessment Objective: internal monitoring capabilities are invoked or monitoring devices are deployed strategically within the system to collect organization-determined essential information;

Assessment Objective: internal monitoring capabilities are invoked or monitoring devices are deployed at ad hoc locations within the system to track specific types of transactions of interest to the organization;

Assessment Objective: detected events are analyzed;

Assessment Objective: detected anomalies are analyzed;

Assessment Objective: the level of system monitoring activity is adjusted when there is a change in risk to organizational operations and assets, individuals, other organizations, or the Nation;

Assessment Objective: a legal opinion regarding system monitoring activities is obtained;

Assessment Objective: {{ insert: param, si-04_odp.03 }} is provided to {{ insert: param, si-04_odp.04 }} {{ insert: param, si-04_odp.05 }}.

System and information integrity policy

system and information integrity procedures

procedures addressing system monitoring tools and techniques

continuous monitoring strategy

facility diagram/layout

system design documentation

system monitoring tools and techniques documentation

locations within the system where monitoring devices are deployed

system configuration settings and associated documentation

system security plan

other relevant documents or records

System/network administrators

organizational personnel with information security responsibilities

organizational personnel installing, configuring, and/or maintaining the system

organizational personnel responsible for monitoring the system

Organizational processes for system monitoring

mechanisms supporting and/or implementing system monitoring capabilities