CIS Controls v8
CIS Control 13: Network Monitoring and Defense

CIS Controls v8 CIS-13.6: Collect Network Traffic Flow Logs

Gather flow logs of network traffic, and/or the traffic itself, from network devices so it can be reviewed and alerted on.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 50 controls across 19 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

NIST SP 800-53 Rev 5 · 8 controls

FedRAMP High · 6 controls

  • CM-8(3) Automated Unauthorized Component Detection
  • IR-5 Incident Monitoring
  • IR-7(1) Incident Response Assistance | Automation Support for Availability of Information and Support (IR-7(1))
  • SI-4 System Monitoring
  • SI-4(18) System Monitoring | Analyze Traffic and Covert Exfiltration (SI-4(18))
  • SI-4(4) Inbound and Outbound Communications Traffic

FedRAMP Moderate · 6 controls

  • CM-8(3) Automated Unauthorized Component Detection
  • IR-5 Incident Monitoring
  • IR-7(1) Incident Response Assistance | Automation Support for Availability of Information and Support (IR-7(1))
  • SI-4 System Monitoring
  • SI-4(18) System Monitoring | Analyze Traffic and Covert Exfiltration (SI-4(18))
  • SI-4(4) Inbound and Outbound Communications Traffic

ISO 27001:2022 · 5 controls

  • 5.7 Threat intelligence
  • 8.15 Logging
  • 8.16 Monitoring activities
  • 8.20 Networks security
  • 8.21 Security of network services

CMMC 2.0 · 4 controls

  • NIST-CSF-DE.AE-03 Information is correlated from multiple sources
  • NIST-CSF-DE.AE-04 The estimated impact and scope of adverse events are understood
  • NIST-CSF-DE.CM-01 Networks and network services are monitored to find potentially adverse events
  • NIST-CSF-ID.AM-03 Representations of the organization's authorized network communication and internal and external network data flows are maintained

C5 (Germany) · 2 controls

  • C5-COS-01 Technical safeguards
  • C5-COS-03 Monitoring of connections in the Cloud Service Provider's network

ISO 27002:2022 · 2 controls

ISO 27701:2019 · 2 controls

  • 5.7.1 Monitoring, measurement, analysis and evaluation
  • 6.9.4 Logging and monitoring

SOC 2 · 2 controls

  • SOC2-CC7.1 CC7.1 Detecting configuration changes and new vulnerabilities
  • SOC2-CC7.2 CC7.2 Monitoring system components for anomalies
  • ASD37-33 Capture network traffic (Limited)
  • SEC04-BP01 Configure service and application logging
  • LT-4 Enable network logging for security investigation

ISO/IEC 42001:2023 · 1 control

  • A.6.2.6 AI system operation and monitoring

NIST SP 800-172 · 1 control

  • 3.14.2e Monitor Organizational Systems with Specialized Capabilities

PCI DSS 4.0 · 1 control

  • 11.5.1.1 11.5.1.1 Service providers detect covert malware channels

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in CIS Control 13: Network Monitoring and Defense

You are reading one control. How much of CIS Controls v8 have you already done?

CIS Controls v8 CIS-13.6 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of CIS Controls v8 your existing evidence covers. Hold ISO 27001:2022 and 102 of 153 CIS Controls v8 controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 240 were rejected on the ISO 27001:2022 pair alone.

Query this from an agent

The graph holds this control, the 50 it maps to, and the evidence behind each claim, over MCP and REST.