id: "SI-04(22)" title: "Unauthorized Network Services" family: "SI" family_name: "System and Information Integrity" sort_id: "si-04.22" priority: "P1" implementation_level: "system" parent: "SI-04" enhancement: True


Detect network services that have not been authorized or approved by {{ insert: param, si-04.22_odp.01 }} ; and

{{ insert: param, si-04.22_odp.02 }} when detected.

Guidance

Unauthorized or unapproved network services include services in service-oriented architectures that lack organizational verification or validation and may therefore be unreliable or serve as malicious rogues for valid services.

Assessment Objective: network services that have not been authorized or approved by {{ insert: param, si-04.22_odp.01 }} are detected;

Assessment Objective: {{ insert: param, si-04.22_odp.02 }} is/are initiated when network services that have not been authorized or approved by authorization or approval processes are detected.

System and information integrity policy

system and information integrity procedures

procedures addressing system monitoring tools and techniques

system design documentation

system monitoring tools and techniques documentation

system configuration settings and associated documentation

documented authorization/approval of network services

notifications or alerts of unauthorized network services

system monitoring logs or records

system audit records

system security plan

other relevant documents or records

System/network administrators

organizational personnel with information security responsibilities

system developer

organizational personnel installing, configuring, and/or maintaining the system

organizational personnel responsible for monitoring the system

Organizational processes for system monitoring

mechanisms supporting and/or implementing a system monitoring capability

mechanisms for auditing network services

mechanisms for providing alerts