id: "SI-04(07)" title: "Automated Response to Suspicious Events" family: "SI" family_name: "System and Information Integrity" sort_id: "si-04.07" priority: "P1" implementation_level: "system" parent: "SI-04" enhancement: True
Notify {{ insert: param, si-04.07_odp.01 }} of detected suspicious events; and
Take the following actions upon detection: {{ insert: param, si-04.07_odp.02 }}.
Guidance
Least-disruptive actions include initiating requests for human responses.
Assessment Objective: {{ insert: param, si-04.07_odp.01 }} are notified of detected suspicious events;
Assessment Objective: {{ insert: param, si-04.07_odp.02 }} are taken upon the detection of suspicious events.
System and information integrity policy
system and information integrity procedures
procedures addressing system monitoring tools and techniques
system design documentation
system monitoring tools and techniques documentation
system configuration settings and associated documentation
alerts and notifications generated based on detected suspicious events
records of actions taken to terminate suspicious events
system audit records
system security plan
other relevant documents or records
System/network administrators
organizational personnel with information security responsibilities
system developers
organizational personnel installing, configuring, and/or maintaining the system
organizational personnel responsible for monitoring the system
organizational personnel responsible for the intrusion detection system
Organizational processes for intrusion detection and system monitoring
mechanisms supporting and/or implementing intrusion detection and system monitoring capabilities
mechanisms supporting and/or implementing notifications to incident response personnel
mechanisms supporting and/or implementing actions to terminate suspicious events