# SI-04 System Monitoring

NIST SP 800-53 control. Family: SI System and Information Integrity. Function: detective. Baselines: low, moderate, high. Mapping licence: CC BY-SA 4.0.

Statement: a. Monitor the system to detect: 1. Attacks and indicators of potential attacks in accordance with the following monitoring objectives: [Assignment: organization-defined monitoring objectives]; and 2. Unauthorized local, network, and remote connections; b. Identify unauthorized use of the system through the following techniques and methods: [Assignment: organization-defined techniques and methods]; c. Invoke internal monitoring capabilities or deploy monitoring devices: 1. Strategically within the system to collect organization-determined essential information; and 2. At ad hoc locations within the system to track specific types of transactions of interest to the organization; d. Analyze detected events and anomalies; e. Adjust the level of system monitoring activity when there is a change in risk to organizational operations and assets, individuals, other organizations, or the Nation; f. Obtain legal opinion regarding system monitoring activities; and g. Provide [Assignment: organization-defined system monitoring information] to [Assignment: organization-defined personnel or roles] [Selection (one or more): as needed; [Assignment: organization-defined frequency]].
Guidance: System monitoring includes external and internal monitoring. External monitoring includes the observation of events occurring at external interfaces to the system. Internal monitoring includes the observation of events occurring within the system. Organizations monitor systems by observing audit activities in real time or by observing other system aspects such as access patterns, characteristics of access, and other actions. The monitoring objectives guide and inform the determination of the events. System monitoring capabilities are achieved through a variety of tools and techniques, including intrusion detection and prevention systems, malicious code protection software, scanning tools, audit record monitoring software, and network monitoring software. Depending on the security architecture, the distribution and configuration of monitoring devices may impact throughput at key internal and external boundaries as well as at other locations across a network due to the introduction of network throughput latency. If throughput management is needed, such devices are strategically located and deployed as part of an established organization-wide security architecture. Strategic locations for monitoring devices include selected perimeter locations and near key servers and server farms that support critical applications. Monitoring devices are typically employed at the managed interfaces associated with controls SC-07 and AC-17. The information collected is a function of the organizational monitoring objectives and the capability of systems to support such objectives. Specific types of transactions of interest include Hypertext Transfer Protocol (HTTP) traffic that bypasses HTTP proxies. System monitoring is an integral part of organizational continuous monitoring and incident response programs, and output from system monitoring serves as input to those programs. System monitoring requirements, including the need for specific types of system monitoring, may be referenced in other controls (e.g., AC-02g, AC-02(07), AC-02(12)(a), AC-17(01), AU-13, AU-13(01), AU-13(02), CM-03f, CM-06d, MA-03a, MA-04a, SC-05(03)(b), SC-07a, SC-07(24)(b), SC-18b, SC-43b). Adjustments to levels of system monitoring are based on law enforcement information, intelligence information, or other sources of information. The legality of system monitoring activities is based on applicable laws, executive orders, directives, regulations, policies, standards, and guidelines.

## Enhancements (23)
- SI-04(01) System-wide Intrusion Detection System
- SI-04(02) Automated Tools and Mechanisms for Real-time Analysis. Baselines: moderate, high
- SI-04(03) Automated Tool and Mechanism Integration
- SI-04(04) Inbound and Outbound Communications Traffic. Baselines: moderate, high
- SI-04(05) System-generated Alerts. Baselines: moderate, high
- SI-04(07) Automated Response to Suspicious Events
- SI-04(09) Testing of Monitoring Tools and Mechanisms
- SI-04(10) Visibility of Encrypted Communications. Baselines: high
- SI-04(11) Analyze Communications Traffic Anomalies
- SI-04(12) Automated Organization-generated Alerts. Baselines: high
- SI-04(13) Analyze Traffic and Event Patterns
- SI-04(14) Wireless Intrusion Detection. Baselines: high
- SI-04(15) Wireless to Wireline Communications
- SI-04(16) Correlate Monitoring Information
- SI-04(17) Integrated Situational Awareness
- SI-04(18) Analyze Traffic and Covert Exfiltration
- SI-04(19) Risk for Individuals
- SI-04(20) Privileged Users. Baselines: high
- SI-04(21) Probationary Periods
- SI-04(22) Unauthorized Network Services. Baselines: high
- SI-04(23) Host-based Devices
- SI-04(24) Indicators of Compromise
- SI-04(25) Optimize Network Traffic Analysis
Withdrawn by NIST: SI-04(06) (now in AC-06(10)); SI-04(08) (now in SI-04).
Each enhancement's statement: /api/v1/controls/SI-04?fields=enhancements

## Patterns that use it (26)
- Critical (10): SP-016 DMZ Module; SP-017 Secure Network Zone Module; SP-023 Industrial Control Systems; SP-025 Advanced Monitoring and Detection; SP-029 Zero Trust Architecture; SP-030 API Security; SP-031 Security Monitoring and Response; SP-036 Incident Response; SP-037 Privileged User Management; SP-049 AI in Security Operations (draft)
- Important (14): SP-001 Client Module; SP-002 Server Module; SP-011 Cloud Computing Pattern; SP-015 Secure Remote Working; SP-026 PCI Full Environment; SP-027 Secure LLM Usage; SP-028 Secure DevOps Pipeline Pattern; SP-032 Modern Authentication; SP-035 Offensive Security Testing; SP-038 Vulnerability Management and Patching; SP-045 AI Governance and Responsible AI; SP-046 External Attack Surface Management; SP-047 Secure Agentic AI Frameworks; SP-048 Offensive AI and Deepfake Defence (draft)
- Standard (2): SP-012 Secure Software Development Lifecycle; SP-043 Security Metrics and Measurement

## Clauses by framework (82 frameworks)
- iso_27001_2022: 9.1, A.8.12, A.8.16. OSA's own, not in NIST's crosswalk: 9.1, A.8.12
- iso_27002_2022: 5.25, 8.12, 8.16
- cobit_2019: DSS01, DSS05, MEA01
- pci_dss_v4: 10.4, 10.7, 11.2, 11.5, 11.6
- nist_csf_2: DE.AE-02, DE.AE-03, DE.AE-04, DE.AE-06, DE.CM-01, DE.CM-03, DE.CM-06, DE.CM-09, ID.IM-01, ID.IM-02, ID.IM-03, ID.RA-01, PR.DS-01, PR.DS-02, PR.DS-10, RS.AN-03. OSA's own, not in NIST's crosswalk: DE.AE-04, DE.AE-06, DE.CM-03, RS.AN-03
- cis_controls_v8: CIS 1.4, CIS 3.13, CIS 8.7, CIS 8.9, CIS 10, CIS 10.7, CIS 13, CIS 13.1, CIS 13.2, CIS 13.3, CIS 13.6, CIS 13.7, CIS 13.8, CIS 13.10, CIS 13.11
- soc2_tsc: CC6.6, CC6.6-POF2, CC7.2, CC7.2-POF1, CC7.3
- finos_ccc: CCC-C08
- iso_42001_2023: A.6.2.6
- iec_62443: 3-3 SR 6.2
- apra_cps_234: Para 22-23
- mas_trm: 11, 12
- pra_op_resilience: SS2/21-7.1
- bsi_grundschutz: DER.1
- anssi: Hygiene.29, Hygiene.39, SecNumCloud.13.7
- osfi_b13: B-13.3.3
- finma_circular: IV.C(66), IV.C(67), IV.C(68), IV.C(69)
- gdpr: Art.32(1)(b), Art.32(1)(d)
- dora: Art.10(1), Art.10(2)
- bio2: 5.25, 8.12, 8.16
- rbi_csf: Annex1.4, Annex1.13, Annex1.16, Annex1.20
- fisc: FISC.O2, FISC.O4
- lgpd_bcb: BCB.Art.3, BCB.Art.6, BCB.Art.7, BCB.PIX, LGPD.Art.46
- hkma_tme1: TME1.5.2, TME1.7.3, TME1.7.5, TME1.10.1, TME1.11.3
- mlps_2: 8.1.3.3, 8.1.4.4, 8.1.4.5, 8.1.5.4, 8.1.10.5, 8.2, 8.3, 8.4, 8.5
- dnb_good_practice: DNB.16.1, DNB.19.1
- cra: CRA.I.2d, CRA.I.2i, CRA.I.2l
- swift_cscf: SWIFT.2.9, SWIFT.6.1, SWIFT.6.4, SWIFT.6.5A
- cbb_tm: TM-8, TM-12, TM-13
- cbuae: CR-3, CR-7
- nca_ecc: 2-4, 2-5, 2-12, 5-1
- qatar_nia: IM, OS
- sama_csf: 3.3, 3.6
- uae_ia: T7, T11
- bog_cisd: CISD-VI, CISD-VII
- bom_ctrm: 3.2, 4.1, 4.2, 5.1
- cbe_csf: CD-1, CTO-6, CTO-7, CTO-8
- cbn_csf: Part2.2, Part3.3, Part3.5, Part4
- popia: s19
- sa_js2: JS2-7.2, JS2-7.3, JS2-7.6, JS2-8.4
- bcbs_239: Principle 10
- bot_cyber: Ch2.6, Ch3.1, Ch8.2
- cpmi_pfmi: CG.DE, PFMI.P17
- eba_ict: 3.4.5, 3.5(c), 3.8(c)
- ecb_croe: CROE.2.3.5, CROE.2.4
- ffiec_is: II.C.9, II.C.12, II.C.16, II.D, III.A, III.B, III.C
- hipaa_sr: §164.308(a)(1)(ii)(D), §164.308(a)(5)(ii)(B), §164.308(a)(5)(ii)(C), §164.308(a)(6)(ii)
- iosco_cyber: DET-1, DET-2, DET-3, DET-4
- nydfs_500: 500.2, 500.6, 500.14
- sebi_cscrf: DE.CM, DE.DP, PR.NS, RS.AN, SOC
- cmmc_2: AU, SI
- nerc_cip: CIP-007-6, CIP-015-1
- nrc_73_54: RG5.71-A-AU, RG5.71-A-SI
- tsa_psd: SD-2 Sec C
- ferc_cip: Order 881
- doe_c2m2: SITUATION
- api_1164: Sec 9
- awia: AWWA Sec 4, AWWA Sec 5
- iaea_nss: Sec 5.5
- pci_pts: I, J, L
- cbest: CBEST.5
- tiber_eu: TIBER.BT
- common_criteria: CC Part 2 — FAU
- isae_3402: Clause 4
- fca_sysc_13: SYSC 13.7.5
- fda_cyber: MON-3, PU-3, SA-5
- hitrust_csf: 09.c, 09.e, 09.g, 11.a, 11.c
- iso_27799: 12.2, 16.2
- lloyds_ms: MS2.1, MS8.5, MS8.10, MS8.12
- naic_ds: 4, 4-audit, 4-monitoring, 4B, 5
- nhs_dspt: NDG-9.3, NDG-9.5, NDG-9.9
- pra_ss1_23: P5.2, P5.3
- solvency_ii: EIOPA-ICT-4.9
- owasp_masvs_v2: MASVS-RESILIENCE-4
- csa_ccm_v4: IVS-09, LOG-03, LOG-05, LOG-13, UEM-11
- csa_aicm: AIS-12, I&S-09, LOG-03, LOG-05, LOG-13, LOG-14, MDS-05, TVM-11, TVM-13, UEM-11
- ccss_v9: 1.02.8, 2.04.2, 2.04.3
- mica: Art.62(5), Art.62(8), Art.68(1), Art.88(1), Art.92(1)
- basel_sco60: SCO60.13, SCO60.51, SCO60.55, SCO60.64, SCO60.65, SCO60.72
- bssc: GSP-12, NOS-06, TIS-05
- sec_custody_digital: SEC-CD-11, SEC-CD-16
- dpdpa: Act.8(5), Rules.6(1)(c), Rules.Sch1.B.7
OSA's mapping for iso_27001_2022 and nist_csf_2 takes NIST's published crosswalk as its base. A clause not marked as OSA's own is in that crosswalk.

## More
- This control as JSON, with guidance and ATT&CK techniques: /api/v1/controls/SI-04
- Clauses only: /api/v1/controls/SI-04?fields=mappings
- Page for people: /controls/si-04/
- Found an error? Open an issue at https://github.com/opensecurityarchitecture/osa-data/issues with the id, what OSA says and what the source says.
