← Controls / SI

SI-04 System Monitoring

System and Information Integrity

Low Moderate High

Description

a. Monitor the system to detect: 1. Attacks and indicators of potential attacks in accordance with the following monitoring objectives: [Assignment: organization-defined monitoring objectives]; and 2. Unauthorized local, network, and remote connections; b. Identify unauthorized use of the system through the following techniques and methods: [Assignment: organization-defined techniques and methods]; c. Invoke internal monitoring capabilities or deploy monitoring devices: 1. Strategically within the system to collect organization-determined essential information; and 2. At ad hoc locations within the system to track specific types of transactions of interest to the organization; d. Analyze detected events and anomalies; e. Adjust the level of system monitoring activity when there is a change in risk to organizational operations and assets, individuals, other organizations, or the Nation; f. Obtain legal opinion regarding system monitoring activities; and g. Provide [Assignment: organization-defined system monitoring information] to [Assignment: organization-defined personnel or roles] [Selection (one or more): as needed; [Assignment: organization-defined frequency]].

Supplemental Guidance

System monitoring includes external and internal monitoring. External monitoring includes the observation of events occurring at external interfaces to the system. Internal monitoring includes the observation of events occurring within the system. Organizations monitor systems by observing audit activities in real time or by observing other system aspects such as access patterns, characteristics of access, and other actions. The monitoring objectives guide and inform the determination of the events. System monitoring capabilities are achieved through a variety of tools and techniques, including intrusion detection and prevention systems, malicious code protection software, scanning tools, audit record monitoring software, and network monitoring software. Depending on the security architecture, the distribution and configuration of monitoring devices may impact throughput at key internal and external boundaries as well as at other locations across a network due to the introduction of network throughput latency. If throughput management is needed, such devices are strategically located and deployed as part of an established organization-wide security architecture. Strategic locations for monitoring devices include selected perimeter locations and near key servers and server farms that support critical applications. Monitoring devices are typically employed at the managed interfaces associated with controls SC-07 and AC-17. The information collected is a function of the organizational monitoring objectives and the capability of systems to support such objectives. Specific types of transactions of interest include Hypertext Transfer Protocol (HTTP) traffic that bypasses HTTP proxies. System monitoring is an integral part of organizational continuous monitoring and incident response programs, and output from system monitoring serves as input to those programs. System monitoring requirements, including the need for specific types of system monitoring, may be referenced in other controls (e.g., AC-02g, AC-02(07), AC-02(12)(a), AC-17(01), AU-13, AU-13(01), AU-13(02), CM-03f, CM-06d, MA-03a, MA-04a, SC-05(03)(b), SC-07a, SC-07(24)(b), SC-18b, SC-43b). Adjustments to levels of system monitoring are based on law enforcement information, intelligence information, or other sources of information. The legality of system monitoring activities is based on applicable laws, executive orders, directives, regulations, policies, standards, and guidelines.

Changes from Rev 4

Title changed from 'Information System Monitoring' Control text replaces 'Protect information obtained from intrusion-monitoring tools from unauthorized access, modification, and deletion' with 'Analyze detected events and anomalies' and replaces 'Heightens' with 'Adjust' Discussion expanded with references to other controls

Enhancements (23)

What NIST adds to this control. Select one to read its statement.

SI-04(01) System-wide Intrusion Detection System

Connect and configure individual intrusion detection tools into a system-wide intrusion detection system.

SI-04(02) Automated Tools and Mechanisms for Real-time Analysis ModerateHigh

Employ automated tools and mechanisms to support near real-time analysis of events.

SI-04(03) Automated Tool and Mechanism Integration

Employ automated tools and mechanisms to integrate intrusion detection tools and mechanisms into access control and flow control mechanisms.

SI-04(04) Inbound and Outbound Communications Traffic ModerateHigh

a. Determine criteria for unusual or unauthorized activities or conditions for inbound and outbound communications traffic; b. Monitor inbound and outbound communications traffic [Assignment: organization-defined frequency] for [Assignment: organization-defined unusual or unauthorized activities or conditions].

SI-04(05) System-generated Alerts ModerateHigh

Alert [Assignment: organization-defined personnel or roles] when the following system-generated indications of compromise or potential compromise occur: [Assignment: organization-defined compromise indicators].

SI-04(07) Automated Response to Suspicious Events

a. Notify [Assignment: organization-defined incident response personnel (identified by name and/or by role)] of detected suspicious events; and b. Take the following actions upon detection: [Assignment: organization-defined least-disruptive actions to terminate suspicious events].

SI-04(09) Testing of Monitoring Tools and Mechanisms

Test intrusion-monitoring tools and mechanisms [Assignment: organization-defined frequency].

SI-04(10) Visibility of Encrypted Communications High

Make provisions so that [Assignment: organization-defined encrypted communications traffic] is visible to [Assignment: organization-defined system monitoring tools and mechanisms].

SI-04(11) Analyze Communications Traffic Anomalies

Analyze outbound communications traffic at the external interfaces to the system and selected [Assignment: organization-defined interior points within the system] to discover anomalies.

SI-04(12) Automated Organization-generated Alerts High

Alert [Assignment: organization-defined personnel or roles] using [Assignment: organization-defined automated mechanisms] when the following indications of inappropriate or unusual activities with security or privacy implications occur: [Assignment: organization-defined activities that trigger alerts].

SI-04(13) Analyze Traffic and Event Patterns

a. Analyze communications traffic and event patterns for the system; b. Develop profiles representing common traffic and event patterns; and c. Use the traffic and event profiles in tuning system-monitoring devices.

SI-04(14) Wireless Intrusion Detection High

Employ a wireless intrusion detection system to identify rogue wireless devices and to detect attack attempts and potential compromises or breaches to the system.

SI-04(15) Wireless to Wireline Communications

Employ an intrusion detection system to monitor wireless communications traffic as the traffic passes from wireless to wireline networks.

SI-04(16) Correlate Monitoring Information

Correlate information from monitoring tools and mechanisms employed throughout the system.

SI-04(17) Integrated Situational Awareness

Correlate information from monitoring physical, cyber, and supply chain activities to achieve integrated, organization-wide situational awareness.

SI-04(18) Analyze Traffic and Covert Exfiltration

Analyze outbound communications traffic at external interfaces to the system and at the following interior points to detect covert exfiltration of information: [Assignment: organization-defined interior points within the system].

SI-04(19) Risk for Individuals

Implement [Assignment: organization-defined additional monitoring] of individuals who have been identified by [Assignment: organization-defined sources] as posing an increased level of risk.

SI-04(20) Privileged Users High

Implement the following additional monitoring of privileged users: [Assignment: organization-defined additional monitoring].

SI-04(21) Probationary Periods

Implement the following additional monitoring of individuals during [Assignment: organization-defined probationary period]: [Assignment: organization-defined additional monitoring].

SI-04(22) Unauthorized Network Services High

a. Detect network services that have not been authorized or approved by [Assignment: organization-defined authorization or approval processes]; and b. [Selection (one or more): Audit; Alert [Assignment: organization-defined personnel or roles]] when detected.

SI-04(23) Host-based Devices

Implement the following host-based monitoring mechanisms at [Assignment: organization-defined system components]: [Assignment: organization-defined host-based monitoring mechanisms].

SI-04(24) Indicators of Compromise

Discover, collect, and distribute to [Assignment: organization-defined personnel or roles], indicators of compromise provided by [Assignment: organization-defined sources].

SI-04(25) Optimize Network Traffic Analysis

Provide visibility into network traffic at external and key internal system interfaces to optimize the effectiveness of monitoring devices.

Withdrawn by NIST:

  • SI-04(06) Restrict Non-privileged Users, now in AC-06(10)
  • SI-04(08) Protection of Monitoring Information, now in SI-04

MITRE ATT&CK Techniques (375)

ATT&CK v16.1

Techniques mitigated by this control, mapped via CTID.

Reconnaissance 4 Initial Access 15 Execution 34 Persistence 79 Privilege Escalation 72 Defense Evasion 131 Credential Access 51 Discovery 9 Lateral Movement 18 Collection 25 Command & Control 36 Exfiltration 14 Impact 19
Show all 375 techniques grouped by tactic

Execution

Persistence

T1037 T1053 T1078 T1098 T1133 T1136 T1137 T1176 T1197 T1205 T1505 T1525 T1543 T1556 T1574 T1653 T1037.002 T1037.003 T1037.004 T1037.005 T1053.002 T1053.003 T1053.005 T1053.006 T1078.001 T1078.002 T1078.003 T1078.004 T1098.001 T1098.002 T1098.003 T1098.004 T1098.007 T1136.001 T1136.002 T1136.003 T1137.001 T1205.001 T1205.002 T1505.002 T1505.003 T1505.004 T1505.005 T1542.004 T1542.005 T1543.002 T1546.002 T1546.003 T1546.004 T1546.006 T1546.008 T1546.013 T1546.014 T1546.016 T1547.002 T1547.003 T1547.004 T1547.005 T1547.006 T1547.007 T1547.008 T1547.009 T1547.012 T1547.013 T1556.001 T1556.002 T1556.003 T1556.004 T1556.008 T1556.009 T1574.001 T1574.004 T1574.005 T1574.007 T1574.008 T1574.009 T1574.010 T1574.013 T1574.014

Privilege Escalation

T1037 T1053 T1055 T1068 T1078 T1098 T1484 T1543 T1548 T1574 T1611 T1037.002 T1037.003 T1037.004 T1037.005 T1053.002 T1053.003 T1053.005 T1053.006 T1055.001 T1055.002 T1055.003 T1055.004 T1055.005 T1055.008 T1055.009 T1055.011 T1055.012 T1055.013 T1055.014 T1078.001 T1078.002 T1078.003 T1078.004 T1098.001 T1098.002 T1098.003 T1098.004 T1098.007 T1543.002 T1546.002 T1546.003 T1546.004 T1546.006 T1546.008 T1546.013 T1546.014 T1546.016 T1547.002 T1547.003 T1547.004 T1547.005 T1547.006 T1547.007 T1547.008 T1547.009 T1547.012 T1547.013 T1548.001 T1548.002 T1548.003 T1548.004 T1548.006 T1574.001 T1574.004 T1574.005 T1574.007 T1574.008 T1574.009 T1574.010 T1574.013 T1574.014

Defense Evasion

T1027 T1036 T1055 T1070 T1078 T1127 T1197 T1205 T1211 T1216 T1218 T1220 T1221 T1222 T1484 T1548 T1553 T1556 T1562 T1574 T1578 T1599 T1601 T1610 T1612 T1622 T1647 T1027.002 T1027.007 T1027.008 T1027.009 T1027.010 T1027.011 T1027.012 T1036.001 T1036.003 T1036.005 T1036.007 T1036.008 T1036.010 T1055.001 T1055.002 T1055.003 T1055.004 T1055.005 T1055.008 T1055.009 T1055.011 T1055.012 T1055.013 T1055.014 T1070.001 T1070.002 T1070.003 T1070.007 T1070.008 T1070.009 T1070.010 T1078.001 T1078.002 T1078.003 T1078.004 T1127.001 T1127.002 T1205.001 T1205.002 T1216.001 T1218.001 T1218.002 T1218.003 T1218.004 T1218.005 T1218.008 T1218.009 T1218.010 T1218.011 T1218.012 T1218.013 T1218.014 T1218.015 T1222.001 T1222.002 T1542.004 T1542.005 T1548.001 T1548.002 T1548.003 T1548.004 T1548.006 T1550.001 T1550.003 T1553.001 T1553.003 T1553.004 T1553.005 T1556.001 T1556.002 T1556.003 T1556.004 T1556.008 T1556.009 T1562.001 T1562.002 T1562.003 T1562.004 T1562.006 T1562.010 T1562.011 T1562.012 T1564.002 T1564.004 T1564.006 T1564.007 T1564.008 T1564.009 T1564.010 T1574.001 T1574.004 T1574.005 T1574.007 T1574.008 T1574.009 T1574.010 T1574.013 T1574.014 T1578.001 T1578.002 T1578.003 T1599.001 T1601.001 T1601.002

Credential Access

T1003 T1040 T1110 T1111 T1187 T1212 T1528 T1539 T1552 T1555 T1556 T1557 T1558 T1003.001 T1003.002 T1003.003 T1003.004 T1003.005 T1003.006 T1003.007 T1003.008 T1056.002 T1110.001 T1110.002 T1110.003 T1110.004 T1552.001 T1552.002 T1552.003 T1552.004 T1552.005 T1552.006 T1552.008 T1555.001 T1555.002 T1555.004 T1555.005 T1556.001 T1556.002 T1556.003 T1556.004 T1556.008 T1556.009 T1557.001 T1557.002 T1557.003 T1557.004 T1558.002 T1558.003 T1558.004 T1558.005

Collection

Command & Control

Compliance Mappings

ISO 27001:2022

9.1A.8.12A.8.16

ISO 27002:2022

5.258.128.16

COBIT 2019

DSS01DSS05MEA01

CIS Controls v8

CIS 1.4CIS 3.13CIS 8.7CIS 8.9CIS 10CIS 10.7CIS 13CIS 13.1CIS 13.2CIS 13.3CIS 13.6CIS 13.7CIS 13.8CIS 13.10CIS 13.11

NIST CSF 2.0

DE.AE-02DE.AE-03DE.AE-04DE.AE-06DE.CM-01DE.CM-03DE.CM-06DE.CM-09ID.IM-01ID.IM-02ID.IM-03ID.RA-01PR.DS-01PR.DS-02PR.DS-10RS.AN-03

SOC 2 TSC

CC6.6CC6.6-POF2CC7.2CC7.2-POF1CC7.3

PCI DSS v4.0.1

10.410.711.211.511.6

CSA CCM v4

IVS-09LOG-03LOG-05LOG-13UEM-11

CSA AICM v1

AIS-12I&S-09LOG-03LOG-05LOG-13LOG-14MDS-05TVM-11TVM-13UEM-11

FINOS CCC

CCC-C08

ISO 42001:2023

A.6.2.6

IEC 62443

3-3 SR 6.2

PRA Operational Resilience

SS2/21-7.1

MAS TRM

1112

APRA CPS 234

Para 22-23

BSI IT-Grundschutz

DER.1

ANSSI

Hygiene.29Hygiene.39SecNumCloud.13.7

FINMA Circular 2023/1

IV.C(66)IV.C(67)IV.C(68)IV.C(69)

OSFI B-13

B-13.3.3

EU GDPR

Art.32(1)(b)Art.32(1)(d)

EU DORA

Art.10(1)Art.10(2)

BIO2

5.258.128.16

RBI CSF

Annex1.4Annex1.13Annex1.16Annex1.20

FISC Security Guidelines

FISC.O2FISC.O4

LGPD + BCB 4893

BCB.Art.3BCB.Art.6BCB.Art.7BCB.PIXLGPD.Art.46

HKMA TM-E-1

TME1.5.2TME1.7.3TME1.7.5TME1.10.1TME1.11.3

MLPS 2.0

8.1.3.38.1.4.48.1.4.58.1.5.48.1.10.58.28.38.48.5

DNB Good Practice

DNB.16.1DNB.19.1

EU CRA

CRA.I.2dCRA.I.2iCRA.I.2l

SWIFT CSCF

SWIFT.2.9SWIFT.6.1SWIFT.6.4SWIFT.6.5A

SAMA CSF

3.33.6

NCA ECC

2-42-52-125-1

UAE IA

T7T11

CBB TM

TM-8TM-12TM-13

Qatar NIA

IMOS

CBUAE

CR-3CR-7

CBE CSF

CD-1CTO-6CTO-7CTO-8

SA JS2

JS2-7.2JS2-7.3JS2-7.6JS2-8.4

CBN CSF

Part2.2Part3.3Part3.5Part4

BoG CISD

CISD-VICISD-VII

POPIA

s19

BoM CTRM

3.24.14.25.1

IOSCO Cyber Resilience

DET-1DET-2DET-3DET-4

BCBS 239

Principle 10

CPMI-IOSCO PFMI

CG.DEPFMI.P17

FFIEC IS

II.C.9II.C.12II.C.16II.DIII.AIII.BIII.C

NYDFS 500

500.2500.6500.14

HIPAA Security Rule

§164.308(a)(1)(ii)(D)§164.308(a)(5)(ii)(B)§164.308(a)(5)(ii)(C)§164.308(a)(6)(ii)

ECB CROE

CROE.2.3.5CROE.2.4

EBA ICT Guidelines

3.4.53.5(c)3.8(c)

SEBI CSCRF

DE.CMDE.DPPR.NSRS.ANSOC

BOT Cyber Resilience

Ch2.6Ch3.1Ch8.2

CMMC 2.0

AUSI

NERC CIP

CIP-007-6CIP-015-1

10 CFR 73.54

RG5.71-A-AURG5.71-A-SI

TSA Pipeline SD

SD-2 Sec C

FERC CIP Orders

Order 881

DOE C2M2 v2.1

SITUATION

API 1164

Sec 9

AWIA

AWWA Sec 4AWWA Sec 5

IAEA NSS 17-T

Sec 5.5

PCI PTS v6

IJL

CBEST

CBEST.5

TIBER-EU

TIBER.BT

Common Criteria

CC Part 2 — FAU

ISAE 3402

Clause 4

Solvency II

EIOPA-ICT-4.9

Lloyd's Minimum Standards

MS2.1MS8.5MS8.10MS8.12

NAIC Insurance Data Security

44-audit4-monitoring4B5

PRA SS1/23

P5.2P5.3

FCA SYSC 13

SYSC 13.7.5

HITRUST CSF v11

09.c09.e09.g11.a11.c

FDA Cybersecurity Guidance

MON-3PU-3SA-5

ISO 27799

12.216.2

NHS DSPT

NDG-9.3NDG-9.5NDG-9.9

OWASP MASVS v2.1

MASVS-RESILIENCE-4

CCSS v9.0

1.02.82.04.22.04.3

MiCA

Art.62(5)Art.62(8)Art.68(1)Art.88(1)Art.92(1)

Basel SCO60

SCO60.13SCO60.51SCO60.55SCO60.64SCO60.65SCO60.72

BSSC Standards

GSP-12NOS-06TIS-05

SEC Custody (Digital Assets)

SEC-CD-11SEC-CD-16

India DPDPA

Act.8(5)Rules.6(1)(c)Rules.Sch1.B.7

ISO 17799 (legacy)

10.6.210.10.110.10.210.10.4

COBIT 4.1 (legacy)

PO2.4DS5.5DS5.10