CMMC 2.0
System and Information Integrity

CMMC 2.0 SI.L2-3.14.7: Identify Unauthorized Use

Define what constitutes authorized use of organizational systems, and identify use that falls outside that definition.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 51 controls across 21 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

NIST SP 800-53 Rev 5 · 6 controls

  • ASBv3-LT-1 Enable threat detection capabilities
  • ASBv3-LT-2 Enable threat detection for identity and access management
  • DP-2 Monitor anomalies and threats targeting sensitive data
  • ES-1 Use Endpoint Detection and Response (EDR)
  • NIST-CSF-DE.AE-02 Potentially adverse events are analyzed to better understand associated activities
  • NIST-CSF-DE.CM-03 Personnel activity and technology usage are monitored to find potentially adverse events
  • NIST-CSF-DE.CM-09 Computing hardware and software, runtime environments, and their data are monitored to find potentially adverse events
  • NIST-CSF-RS.AN-07 Incident data and metadata are collected, and their integrity and provenance are preserved

SOC 2 · 4 controls

  • SOC2-CC6.8 CC6.8 Preventing and detecting unauthorised or malicious software
  • SOC2-CC7.1 CC7.1 Detecting configuration changes and new vulnerabilities
  • SOC2-CC7.2 CC7.2 Monitoring system components for anomalies
  • SOC2-CC7.3 CC7.3 Evaluating security events to identify incidents

CIS Controls v8 · 3 controls

  • CIS-1.2 Address Unauthorized Assets
  • CIS-13.2 Deploy a Host-Based Intrusion Detection Solution
  • CIS-8.11 Conduct Audit Log Reviews

FedRAMP High · 3 controls

  • AC-2(12) Account Monitoring for Atypical Usage
  • SI-4 System Monitoring
  • SI-4(5) System-Generated Alerts

FedRAMP Moderate · 3 controls

  • AC-2(12) Account Monitoring for Atypical Usage
  • SI-4 System Monitoring
  • SI-4(5) System-Generated Alerts

ISO 27001:2022 · 3 controls

  • 5.25 Assessment and decision on information security events
  • 8.15 Logging
  • 8.16 Monitoring activities

NIST SP 800-172 · 3 controls

  • 3.11.2e Threat Hunting
  • 3.14.2e Monitor Organizational Systems with Specialized Capabilities
  • 3.4.2e Automated Detection and Remediation of Unauthorized Software
  • ASD37-27 Outbound data loss prevention (Very Good)
  • ASD37-31 Hunt to discover incidents (Very Good)

HIPAA Security Rule · 2 controls

NIST SP 800-66 Rev 2 · 2 controls

  • E8-APP-ML3 Application Control (ML3)

C5 (Germany) · 1 control

  • C5-OPS-15 Logging and Monitoring - Accountability

ISO 27002:2022 · 1 control

  • 8.16 Monitoring activities

ISO 27701:2019 · 1 control

  • 6.9.4 Logging and monitoring

PCI DSS 4.0 · 1 control

  • 10.2.1.4 10.2.1.4 Logs capture invalid logical access attempts

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in System and Information Integrity

You are reading one control. How much of CMMC 2.0 have you already done?

CMMC 2.0 SI.L2-3.14.7 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of CMMC 2.0 your existing evidence covers. Hold FedRAMP Moderate and 108 of 110 CMMC 2.0 controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 1 were rejected on the FedRAMP Moderate pair alone.

Query this from an agent

The graph holds this control, the 51 it maps to, and the evidence behind each claim, over MCP and REST.