id: "SI-05" title: "Security Alerts, Advisories, and Directives" family: "SI" family_name: "System and Information Integrity" sort_id: "si-05" priority: "P1" implementation_level: "organization" enhancements: - si-5.1


Receive system security alerts, advisories, and directives from {{ insert: param, si-05_odp.01 }} on an ongoing basis;

Generate internal security alerts, advisories, and directives as deemed necessary;

Disseminate security alerts, advisories, and directives to: {{ insert: param, si-05_odp.02 }} ; and

Implement security directives in accordance with established time frames, or notify the issuing organization of the degree of noncompliance.

Guidance

The Cybersecurity and Infrastructure Security Agency (CISA) generates security alerts and advisories to maintain situational awareness throughout the Federal Government. Security directives are issued by OMB or other designated organizations with the responsibility and authority to issue such directives. Compliance with security directives is essential due to the critical nature of many of these directives and the potential (immediate) adverse effects on organizational operations and assets, individuals, other organizations, and the Nation should the directives not be implemented in a timely manner. External organizations include supply chain partners, external mission or business partners, external service providers, and other peer or supporting organizations.

Assessment Objective: system security alerts, advisories, and directives are received from {{ insert: param, si-05_odp.01 }} on an ongoing basis;

Assessment Objective: internal security alerts, advisories, and directives are generated as deemed necessary;

Assessment Objective: security alerts, advisories, and directives are disseminated to {{ insert: param, si-05_odp.02 }};

Assessment Objective: security directives are implemented in accordance with established time frames or if the issuing organization is notified of the degree of noncompliance.

System and information integrity policy

system and information integrity procedures

procedures addressing security alerts, advisories, and directives

records of security alerts and advisories

system security plan

other relevant documents or records

Organizational personnel with security alert and advisory responsibilities

organizational personnel implementing, operating, maintaining, and using the system

organizational personnel, organizational elements, and/or external organizations to whom alerts, advisories, and directives are to be disseminated

system/network administrators

organizational personnel with information security responsibilities

Organizational processes for defining, receiving, generating, disseminating, and complying with security alerts, advisories, and directives

mechanisms supporting and/or implementing the definition, receipt, generation, and dissemination of security alerts, advisories, and directives

mechanisms supporting and/or implementing security directives