← Controls / AU

AU-13 Monitoring for Information Disclosure

Audit and Accountability

Description

a. Monitor [Assignment: organization-defined open-source information and/or information sites] [Assignment: organization-defined frequency] for evidence of unauthorized disclosure of organizational information; and b. If an information disclosure is discovered: 1. Notify [Assignment: organization-defined personnel or roles]; and 2. Take the following additional actions: [Assignment: organization-defined additional actions].

Supplemental Guidance

Unauthorized disclosure of information is a form of data leakage. Open-source information includes social networking sites and code-sharing platforms and repositories. Examples of organizational information include personally identifiable information retained by the organization or proprietary information generated by the organization.

Changes from Rev 4

No significant changes from Rev 4.

Enhancements (3)

What NIST adds to this control. Select one to read its statement.

AU-13(01) Use of Automated Tools

Monitor open-source information and information sites using [Assignment: organization-defined automated mechanisms].

AU-13(02) Review of Monitored Sites

Review the list of open-source information sites being monitored [Assignment: organization-defined frequency].

AU-13(03) Unauthorized Replication of Information

Employ discovery techniques, processes, and tools to determine if external entities are replicating organizational information in an unauthorized manner.

Compliance Mappings

ISO 27001:2022

7.5A.8.12A.8.16

NIST CSF 2.0

DE.CM-03PR.DS-10

RBI CSF

Annex1.16

MLPS 2.0

8.1.5.2

NCA ECC

2-12

Qatar NIA

OS

CBE CSF

CD-1

CBN CSF

Part9

BoM CTRM

4.2

IOSCO Cyber Resilience

DET-1

CPMI-IOSCO PFMI

CG.DECG.SA

FFIEC IS

II.DIII.B

NYDFS 500

500.14

HIPAA Security Rule

§164.308(a)(1)(ii)(D)

ECB CROE

CROE.2.4CROE.2.7.1

EBA ICT Guidelines

3.4.5

SEBI CSCRF

DE.CM

BOT Cyber Resilience

Ch3.1

CMMC 2.0

AU

CBEST

CBEST.5

Common Criteria

CC Part 2 — FAU

Lloyd's Minimum Standards

MS8.12