id: "SI-04(04)" title: "Inbound and Outbound Communications Traffic" family: "SI" family_name: "System and Information Integrity" sort_id: "si-04.04" priority: "P1" implementation_level: "system" parent: "SI-04" enhancement: True


Determine criteria for unusual or unauthorized activities or conditions for inbound and outbound communications traffic;

Monitor inbound and outbound communications traffic {{ insert: param, si-4.4_prm_1 }} for {{ insert: param, si-4.4_prm_2 }}.

Guidance

Unusual or unauthorized activities or conditions related to system inbound and outbound communications traffic includes internal traffic that indicates the presence of malicious code or unauthorized use of legitimate code or credentials within organizational systems or propagating among system components, signaling to external systems, and the unauthorized exporting of information. Evidence of malicious code or unauthorized use of legitimate code or credentials is used to identify potentially compromised systems or system components.

Assessment Objective: criteria for unusual or unauthorized activities or conditions for inbound communications traffic are defined;

Assessment Objective: criteria for unusual or unauthorized activities or conditions for outbound communications traffic are defined;

Assessment Objective: inbound communications traffic is monitored {{ insert: param, si-04.04_odp.01 }} for {{ insert: param, si-04.04_odp.02 }};

Assessment Objective: outbound communications traffic is monitored {{ insert: param, si-04.04_odp.03 }} for {{ insert: param, si-04.04_odp.04 }}.

System and information integrity policy

system and information integrity procedures

procedures addressing system monitoring tools and techniques

system design documentation

system monitoring tools and techniques documentation

system configuration settings and associated documentation

system protocols

system audit records

system security plan

other relevant documents or records

System/network administrators

organizational personnel with information security responsibilities

organizational personnel installing, configuring, and/or maintaining the system

organizational personnel responsible for monitoring the system

organizational personnel responsible for the intrusion detection system

Organizational processes for intrusion detection and system monitoring

mechanisms supporting and/or implementing intrusion detection and system monitoring capabilities

mechanisms supporting and/or implementing the monitoring of inbound and outbound communications traffic