AU-13 Monitoring for Information Disclosure
Audit and Accountability
Description
a. Monitor [Assignment: organization-defined open-source information and/or information sites] [Assignment: organization-defined frequency] for evidence of unauthorized disclosure of organizational information; and b. If an information disclosure is discovered: 1. Notify [Assignment: organization-defined personnel or roles]; and 2. Take the following additional actions: [Assignment: organization-defined additional actions].
Supplemental Guidance
Unauthorized disclosure of information is a form of data leakage. Open-source information includes social networking sites and code-sharing platforms and repositories. Examples of organizational information include personally identifiable information retained by the organization or proprietary information generated by the organization.
Changes from Rev 4
No significant changes from Rev 4.
Enhancements (3)
What NIST adds to this control. Select one to read its statement.
AU-13(01) Use of Automated Tools
Monitor open-source information and information sites using [Assignment: organization-defined automated mechanisms].
AU-13(02) Review of Monitored Sites
Review the list of open-source information sites being monitored [Assignment: organization-defined frequency].
AU-13(03) Unauthorized Replication of Information
Employ discovery techniques, processes, and tools to determine if external entities are replicating organizational information in an unauthorized manner.