NIST SP 800-171 Rev 3
03.14 SI (System and Information Integrity)

NIST SP 800-171 Rev 3 03.14.03: Security Alerts, Advisories, and Directives

Receive system security alerts, advisories, and directives from external organizations on an ongoing basis; generate internal alerts/advisories; disseminate.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 35 controls across 22 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

ISO 27002:2022 · 3 controls

  • 5.6 Contact with special interest groups
  • 5.7 Threat intelligence
  • 8.8 Management of technical vulnerabilities
  • NIST-CSF-DE.AE-06 Information on adverse events is provided to authorized staff and tools
  • NIST-CSF-DE.AE-07 Cyber threat intelligence and other contextual information are integrated into the analysis
  • NIST-CSF-ID.RA-02 Cyber threat intelligence is received from information sharing forums and sources

NIST SP 800-161 Rev 1 · 3 controls

  • SEC01-BP04 Stay up to date with security threats and recommendations
  • SEC01-BP08 Evaluate and implement new security services and features regularly

C5 (Germany) · 2 controls

  • C5-OIS-05 Contact with Relevant Government Agencies and Interest Groups
  • C5-PSS-03 Online Register of Known Vulnerabilities

ISO 27001:2022 · 2 controls

  • 5.6 Contact with special interest groups
  • 5.7 Threat intelligence

NIS2 Directive · 2 controls

  • Art.21.3 Take account of supplier-specific vulnerabilities and of Union coordinated supply chain risk assessments
  • Art.23.2 Tell affected service recipients about significant cyber threats and the remedies open to them

SOC 2 · 2 controls

  • SOC2-CC2.3 CC2.3 Communication with external parties about internal control (COSO principle 15)
  • SOC2-CC7.1 CC7.1 Detecting configuration changes and new vulnerabilities

APRA CPS 234 · 1 control

  • CPS234-P17 Active Maintenance of Capability Against Change
  • ASBv3-IR-2 Preparation - setup incident notification

CIS Controls v8 · 1 control

  • CIS-7.1 Establish and Maintain a Vulnerability Management Process

CMMC 2.0 · 1 control

FedRAMP High · 1 control

  • SI-5 Security Alerts, Advisories, and Directives

FedRAMP Moderate · 1 control

  • SI-5 Security Alerts, Advisories, and Directives

HIPAA Security Rule · 1 control

NIST SP 800-172 · 1 control

  • 3.14.6e Use Threat Indicator Information for Detection

NIST SP 800-218 · 1 control

  • NIST800-SI-5 SI-5 Security Alerts, Advisories, and Directives

PCI DSS 4.0 · 1 control

  • 6.3.1 6.3.1 Vulnerability identification and risk ranking

UK Cyber Essentials · 1 control

  • CE-SU.3 Critical and High Updates within 14 Days

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in 03.14 SI (System and Information Integrity)

You are reading one control. How much of NIST SP 800-171 Rev 3 have you already done?

NIST SP 800-171 Rev 3 03.14.03 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of NIST SP 800-171 Rev 3 your existing evidence covers. Hold PCI DSS 4.0 and 69 of 97 NIST SP 800-171 Rev 3 controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 0 were rejected on the PCI DSS 4.0 pair alone.

Query this from an agent

The graph holds this control, the 35 it maps to, and the evidence behind each claim, over MCP and REST.