id: "SI-04(13)" title: "Analyze Traffic and Event Patterns" family: "SI" family_name: "System and Information Integrity" sort_id: "si-04.13" priority: "P1" implementation_level: "system" parent: "SI-04" enhancement: True
Analyze communications traffic and event patterns for the system;
Develop profiles representing common traffic and event patterns; and
Use the traffic and event profiles in tuning system-monitoring devices.
Guidance
Identifying and understanding common communications traffic and event patterns help organizations provide useful information to system monitoring devices to more effectively identify suspicious or anomalous traffic and events when they occur. Such information can help reduce the number of false positives and false negatives during system monitoring.
Assessment Objective: communications traffic for the system is analyzed;
Assessment Objective: event patterns for the system are analyzed;
Assessment Objective: profiles representing common traffic are developed;
Assessment Objective: profiles representing event patterns are developed;
Assessment Objective: traffic profiles are used in tuning system-monitoring devices;
Assessment Objective: event profiles are used in tuning system-monitoring devices.
System and information integrity policy
system and information integrity procedures
procedures addressing system monitoring tools and techniques
system design documentation
system monitoring tools and techniques documentation
system configuration settings and associated documentation
list of profiles representing common traffic patterns and/or events
system protocols documentation
list of acceptable thresholds for false positives and false negatives
system security plan
other relevant documents or records
System/network administrators
organizational personnel with information security responsibilities
organizational personnel installing, configuring, and/or maintaining the system
organizational personnel responsible for monitoring the system
organizational personnel responsible for the intrusion detection system
Organizational processes for intrusion detection and system monitoring
mechanisms supporting and/or implementing intrusion detection and system monitoring capabilities
mechanisms supporting and/or implementing the analysis of communications traffic and event patterns