id: "SI-04(05)" title: "System-generated Alerts" family: "SI" family_name: "System and Information Integrity" sort_id: "si-04.05" priority: "P1" implementation_level: "system" parent: "SI-04" enhancement: True


Statement

Alert {{ insert: param, si-04.05_odp.01 }} when the following system-generated indications of compromise or potential compromise occur: {{ insert: param, si-04.05_odp.02 }}.

Guidance

Alerts may be generated from a variety of sources, including audit records or inputs from malicious code protection mechanisms, intrusion detection or prevention mechanisms, or boundary protection devices such as firewalls, gateways, and routers. Alerts can be automated and may be transmitted telephonically, by electronic mail messages, or by text messaging. Organizational personnel on the alert notification list can include system administrators, mission or business owners, system owners, information owners/stewards, senior agency information security officers, senior agency officials for privacy, system security officers, or privacy officers. In contrast to alerts generated by the system, alerts generated by organizations in SI-4(12) focus on information sources external to the system, such as suspicious activity reports and reports on potential insider threats.

Assessment Objective

{{ insert: param, si-04.05_odp.01 }} are alerted when system-generated {{ insert: param, si-04.05_odp.02 }} occur.

System and information integrity policy

system and information integrity procedures

procedures addressing system monitoring tools and techniques

system monitoring tools and techniques documentation

system configuration settings and associated documentation

list of personnel selected to receive alerts

documentation of alerts generated based on compromise indicators

system audit records

system security plan

privacy plan

other relevant documents or records

System/network administrators

organizational personnel with information security and privacy responsibilities

system developers

organizational personnel installing, configuring, and/or maintaining the system

organizational personnel responsible for monitoring the system

organizational personnel on the system alert notification list

organizational personnel responsible for the intrusion detection system

Organizational processes for intrusion detection and system monitoring

mechanisms supporting and/or implementing intrusion detection and system monitoring capabilities

mechanisms supporting and/or implementing alerts for compromise indicators