id: "SI-05" title: "Security Alerts, Advisories, and Directives" family: "SI" family_name: "System and Information Integrity" sort_id: "si-05" priority: "P1" implementation_level: "organization" enhancements: - si-5.1
Receive system security alerts, advisories, and directives from {{ insert: param, si-05_odp.01 }} on an ongoing basis;
Generate internal security alerts, advisories, and directives as deemed necessary;
Disseminate security alerts, advisories, and directives to: {{ insert: param, si-05_odp.02 }} ; and
Implement security directives in accordance with established time frames, or notify the issuing organization of the degree of noncompliance.
Guidance
The Cybersecurity and Infrastructure Security Agency (CISA) generates security alerts and advisories to maintain situational awareness throughout the Federal Government. Security directives are issued by OMB or other designated organizations with the responsibility and authority to issue such directives. Compliance with security directives is essential due to the critical nature of many of these directives and the potential (immediate) adverse effects on organizational operations and assets, individuals, other organizations, and the Nation should the directives not be implemented in a timely manner. External organizations include supply chain partners, external mission or business partners, external service providers, and other peer or supporting organizations.
Assessment Objective: system security alerts, advisories, and directives are received from {{ insert: param, si-05_odp.01 }} on an ongoing basis;
Assessment Objective: internal security alerts, advisories, and directives are generated as deemed necessary;
Assessment Objective: security alerts, advisories, and directives are disseminated to {{ insert: param, si-05_odp.02 }};
Assessment Objective: security directives are implemented in accordance with established time frames or if the issuing organization is notified of the degree of noncompliance.
System and information integrity policy
system and information integrity procedures
procedures addressing security alerts, advisories, and directives
records of security alerts and advisories
system security plan
other relevant documents or records
Organizational personnel with security alert and advisory responsibilities
organizational personnel implementing, operating, maintaining, and using the system
organizational personnel, organizational elements, and/or external organizations to whom alerts, advisories, and directives are to be disseminated
system/network administrators
organizational personnel with information security responsibilities
Organizational processes for defining, receiving, generating, disseminating, and complying with security alerts, advisories, and directives
mechanisms supporting and/or implementing the definition, receipt, generation, and dissemination of security alerts, advisories, and directives
mechanisms supporting and/or implementing security directives