id: "SI-04(13)" title: "Analyze Traffic and Event Patterns" family: "SI" family_name: "System and Information Integrity" sort_id: "si-04.13" priority: "P1" implementation_level: "system" parent: "SI-04" enhancement: True


Analyze communications traffic and event patterns for the system;

Develop profiles representing common traffic and event patterns; and

Use the traffic and event profiles in tuning system-monitoring devices.

Guidance

Identifying and understanding common communications traffic and event patterns help organizations provide useful information to system monitoring devices to more effectively identify suspicious or anomalous traffic and events when they occur. Such information can help reduce the number of false positives and false negatives during system monitoring.

Assessment Objective: communications traffic for the system is analyzed;

Assessment Objective: event patterns for the system are analyzed;

Assessment Objective: profiles representing common traffic are developed;

Assessment Objective: profiles representing event patterns are developed;

Assessment Objective: traffic profiles are used in tuning system-monitoring devices;

Assessment Objective: event profiles are used in tuning system-monitoring devices.

System and information integrity policy

system and information integrity procedures

procedures addressing system monitoring tools and techniques

system design documentation

system monitoring tools and techniques documentation

system configuration settings and associated documentation

list of profiles representing common traffic patterns and/or events

system protocols documentation

list of acceptable thresholds for false positives and false negatives

system security plan

other relevant documents or records

System/network administrators

organizational personnel with information security responsibilities

organizational personnel installing, configuring, and/or maintaining the system

organizational personnel responsible for monitoring the system

organizational personnel responsible for the intrusion detection system

Organizational processes for intrusion detection and system monitoring

mechanisms supporting and/or implementing intrusion detection and system monitoring capabilities

mechanisms supporting and/or implementing the analysis of communications traffic and event patterns