id: "SI-04(07)" title: "Automated Response to Suspicious Events" family: "SI" family_name: "System and Information Integrity" sort_id: "si-04.07" priority: "P1" implementation_level: "system" parent: "SI-04" enhancement: True


Notify {{ insert: param, si-04.07_odp.01 }} of detected suspicious events; and

Take the following actions upon detection: {{ insert: param, si-04.07_odp.02 }}.

Guidance

Least-disruptive actions include initiating requests for human responses.

Assessment Objective: {{ insert: param, si-04.07_odp.01 }} are notified of detected suspicious events;

Assessment Objective: {{ insert: param, si-04.07_odp.02 }} are taken upon the detection of suspicious events.

System and information integrity policy

system and information integrity procedures

procedures addressing system monitoring tools and techniques

system design documentation

system monitoring tools and techniques documentation

system configuration settings and associated documentation

alerts and notifications generated based on detected suspicious events

records of actions taken to terminate suspicious events

system audit records

system security plan

other relevant documents or records

System/network administrators

organizational personnel with information security responsibilities

system developers

organizational personnel installing, configuring, and/or maintaining the system

organizational personnel responsible for monitoring the system

organizational personnel responsible for the intrusion detection system

Organizational processes for intrusion detection and system monitoring

mechanisms supporting and/or implementing intrusion detection and system monitoring capabilities

mechanisms supporting and/or implementing notifications to incident response personnel

mechanisms supporting and/or implementing actions to terminate suspicious events