{"data":{"id":"AU-13","name":"Monitoring for Information Disclosure","family":"AU","family_name":"Audit and Accountability","withdrawn":false,"description":"a. Monitor [Assignment: organization-defined open-source information and/or information sites] [Assignment: organization-defined frequency] for evidence of unauthorized disclosure of organizational information; and\nb. If an information disclosure is discovered:\n1. Notify [Assignment: organization-defined personnel or roles]; and\n2. Take the following additional actions: [Assignment: organization-defined additional actions].","supplemental_guidance":"Unauthorized disclosure of information is a form of data leakage. Open-source information includes social networking sites and code-sharing platforms and repositories. Examples of organizational information include personally identifiable information retained by the organization or proprietary information generated by the organization.","enhancements":[{"id":"AU-13(01)","name":"Use of Automated Tools","statement":"Monitor open-source information and information sites using [Assignment: organization-defined automated mechanisms].","baselines":[]},{"id":"AU-13(02)","name":"Review of Monitored Sites","statement":"Review the list of open-source information sites being monitored [Assignment: organization-defined frequency].","baselines":[]},{"id":"AU-13(03)","name":"Unauthorized Replication of Information","statement":"Employ discovery techniques, processes, and tools to determine if external entities are replicating organizational information in an unauthorized manner.","baselines":[]}],"baseline_low":false,"baseline_moderate":false,"baseline_high":false,"nist_800_53":{"rev5":{"id":"AU-13","name":"Monitoring for Information Disclosure","description":"a. Monitor [Assignment: organization-defined open-source information and/or information sites] [Assignment: organization-defined frequency] for evidence of unauthorized disclosure of organizational information; and\nb. If an information disclosure is discovered:\n1. Notify [Assignment: organization-defined personnel or roles]; and\n2. Take the following additional actions: [Assignment: organization-defined additional actions].","discussion":"Unauthorized disclosure of information is a form of data leakage. Open-source information includes social networking sites and code-sharing platforms and repositories. Examples of organizational information include personally identifiable information retained by the organization or proprietary information generated by the organization.","related_controls":["AC-22","PE-03","PM-12","RA-05","SC-07","SI-20"],"baseline_low":false,"baseline_moderate":false,"baseline_high":false,"baseline_privacy":false,"new_in_rev5":false,"changes_from_rev4":"No significant changes from Rev 4."}},"compliance_mappings":{"iso_27001_2022":["7.5","A.8.12","A.8.16"],"iso_27002_2022":[],"cobit_2019":[],"pci_dss_v4":[],"nist_csf_2":["DE.CM-03","PR.DS-10"],"cis_controls_v8":[],"soc2_tsc":[],"finos_ccc":[],"iso_42001_2023":[],"iec_62443":[],"asd_e8":[],"nis2":[],"apra_cps_234":[],"mas_trm":[],"pra_op_resilience":[],"bsi_grundschutz":[],"anssi":[],"osfi_b13":[],"finma_circular":[],"gdpr":[],"dora":[],"bio2":[],"rbi_csf":["Annex1.16"],"fisc":[],"lgpd_bcb":[],"hkma_tme1":[],"mlps_2":["8.1.5.2"],"dnb_good_practice":[],"cra":[],"swift_cscf":[],"nca_ecc":["2-12"],"qatar_nia":["OS"],"bom_ctrm":["4.2"],"cbe_csf":["CD-1"],"cbn_csf":["Part9"],"bot_cyber":["Ch3.1"],"cpmi_pfmi":["CG.DE","CG.SA"],"eba_ict":["3.4.5"],"ecb_croe":["CROE.2.4","CROE.2.7.1"],"ffiec_is":["II.D","III.B"],"hipaa_sr":["§164.308(a)(1)(ii)(D)"],"iosco_cyber":["DET-1"],"nydfs_500":["500.14"],"sebi_cscrf":["DE.CM"],"cmmc_2":["AU"],"nerc_cip":[],"nrc_73_54":[],"tsa_psd":[],"ieee_1686":[],"ferc_cip":[],"doe_c2m2":[],"api_1164":[],"awia":[],"iaea_nss":[],"pci_pts":[],"fips_140":[],"cbest":["CBEST.5"],"tiber_eu":[],"pci_hsm":[],"common_criteria":["CC Part 2 — FAU"],"isae_3402":[],"fca_sysc_13":[],"fda_21_cfr_11":[],"fda_cyber":[],"hitrust_csf":[],"iso_27799":[],"lloyds_ms":["MS8.12"],"naic_ds":[],"nhs_dspt":[],"pra_ss1_23":[],"solvency_ii":[],"owasp_masvs_v2":[],"csa_ccm_v4":[],"csa_aicm":[],"ccss_v9":[],"mica":[],"basel_sco60":[],"bssc":[],"sec_custody_digital":[],"dpdpa":[]},"attack_techniques":[],"metadata":{"last_reviewed":"2026-10-03","review_notes":"Generated from NIST SP 800-53 Rev 5 with compliance mappings from framework-coverage data 2026-10-03: iso_27001_2022 A.8.12, A.8.16 added from NIST's SP 800-53 Rev 5 to ISO/IEC 27001:2022 crosswalk (OLIR entry 155), which OSA's mapping now takes as its base. 2026-10-03: nist_csf_2 DE.CM-03, PR.DS-10 added from NIST's CSF 2.0 to SP 800-53 Rev 5.2.0 crosswalk (OLIR entry 186), which OSA's mapping now takes as its base.","mapping_status":"complete"},"function":"detective","used_by_patterns":[]}}