Frameworks / NIST SP 800-53 Rev 5 / NIST800-SI-4 NIST SP 800-53 Rev 5
SI - System and Information Integrity
NIST SP 800-53 Rev 5 NIST800-SI-4: SI-4 System Monitoring a. Monitor the system to detect: 1. Attacks and indicators of potential attacks in accordance with the following monitoring objectives: [Assignment: organization-defined monitoring objectives]; and 2. Unauthorized local, network, and remote connections; b. Identify unauthorized use of the system through the following techniques and methods: [Assignment: organization-defined techniques and methods]; c. Invoke internal monitoring capabilities or deploy monitoring devices: 1. Strategically within the system to collect organization-determined essential information; and 2. At ad hoc locations within the system to track specific types of transactions of interest to the organization; d. Analyze detected events and anomalies; e. Adjust the level of system monitoring activity when there is a change in risk to organizational operations and assets, individuals, other organizations, or the Nation; f. Obtain legal opinion regarding system monitoring activities; and g. Provide [Assignment: organization-defined system monitoring information] to [Assignment: organization-defined personnel or roles] [Selection (one or more): as needed; [Assignment: organization-defined frequency]].
Maintained by Gerard Blokdyk · Verified against the published standard 31 May 2026 · Control text last updated 21 May 2026 What else in your programme already covers this This control maps to 153 controls across 44 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
AC-2(12) Account Monitoring for Atypical Usage AU-6(3) Correlate Audit Record Repositories CA-7 Continuous Monitoring CA-7(4) Continuous Monitoring | Risk Monitoring (CA-7(4)) CM-8(3) Automated Unauthorized Component Detection SC-5 Denial-of-Service Protection SI-4 System Monitoring SI-4(1) System Monitoring | System-wide Intrusion Detection System (SI-4(1)) SI-4(16) System Monitoring | Correlate Monitoring Information (SI-4(16)) SI-4(18) System Monitoring | Analyze Traffic and Covert Exfiltration (SI-4(18)) SI-4(2) Automated Tools and Mechanisms for Real-Time Analysis SI-4(23) System Monitoring | Host-based Devices (SI-4(23)) SI-4(4) Inbound and Outbound Communications Traffic SI-4(5) System-Generated Alerts AC-2(12) Account Monitoring for Atypical Usage AU-6(3) Correlate Audit Record Repositories CA-7 Continuous Monitoring CA-7(4) Continuous Monitoring | Risk Monitoring (CA-7(4)) CM-8(3) Automated Unauthorized Component Detection SC-5 Denial-of-Service Protection SI-4 System Monitoring SI-4(1) System Monitoring | System-wide Intrusion Detection System (SI-4(1)) SI-4(16) System Monitoring | Correlate Monitoring Information (SI-4(16)) SI-4(18) System Monitoring | Analyze Traffic and Covert Exfiltration (SI-4(18)) SI-4(2) Automated Tools and Mechanisms for Real-Time Analysis SI-4(23) System Monitoring | Host-based Devices (SI-4(23)) SI-4(4) Inbound and Outbound Communications Traffic SI-4(5) System-Generated Alerts CIS-1.2 Address Unauthorized Assets CIS-1.5 Use a Passive Asset Discovery Tool CIS-10.7 Use Behavior-Based Anti-Malware Software CIS-13.1 Centralize Security Event Alerting CIS-13.11 Tune Security Event Alerting Thresholds CIS-13.2 Deploy a Host-Based Intrusion Detection Solution CIS-13.3 Deploy a Network Intrusion Detection Solution CIS-13.6 Collect Network Traffic Flow Logs CIS-13.7 Deploy a Host-Based Intrusion Prevention Solution CIS-13.8 Deploy a Network Intrusion Prevention Solution CIS-8.11 Conduct Audit Log Reviews CIS-8.2 Collect Audit Logs CIS-8.8 Collect Command-Line Audit Logs 10.4.1 10.4.1 Daily review of security-relevant logs 10.4.2 10.4.2 Periodic review of all other system component logs 10.4.3 10.4.3 Exceptions and anomalies from log review addressed 10.7.1 10.7.1 Service providers detect critical control failures (superseded) 10.7.2 10.7.2 Detect and alert on critical security control failures 11.2.1 11.2.1 Detect authorized and rogue wireless access points 11.5.1 11.5.1 IDS/IPS monitoring of CDE traffic 11.5.1.1 11.5.1.1 Service providers detect covert malware channels 11.5.2 11.5.2 Change detection on critical files 12.1.3 12.1.3 Security roles defined and acknowledged by all personnel 12.10.5 12.10.5 Plan covers alerts from security monitoring systems 12.10.7 12.10.7 Response procedures for PAN found in unexpected locations 6.4.2 6.4.2 Automated web attack detection and prevention NIST-CSF-DE.AE-02 Potentially adverse events are analyzed to better understand associated activities NIST-CSF-DE.AE-03 Information is correlated from multiple sources NIST-CSF-DE.AE-06 Information on adverse events is provided to authorized staff and tools NIST-CSF-DE.AE-07 Cyber threat intelligence and other contextual information are integrated into the analysis NIST-CSF-DE.CM-01 Networks and network services are monitored to find potentially adverse events NIST-CSF-DE.CM-03 Personnel activity and technology usage are monitored to find potentially adverse events NIST-CSF-DE.CM-06 External service provider activities and services are monitored to find potentially adverse events NIST-CSF-DE.CM-09 Computing hardware and software, runtime environments, and their data are monitored to find potentially adverse events NIST-CSF-PR.PS-04 Log records are generated and made available for continuous monitoring NIST-CSF-RS.AN-03 Analysis is performed to establish what has taken place during an incident and the root cause of the incident NIST-CSF-RS.MI-01 Incidents are contained ASBv3-IR-3 Detection and analysis - create incidents based on high-quality alerts ASBv3-LT-1 Enable threat detection capabilities ASBv3-LT-2 Enable threat detection for identity and access management ASBv3-NS-4 Deploy intrusion detection/intrusion prevention systems (IDS/IPS) DP-2 Monitor anomalies and threats targeting sensitive data ES-1 Use Endpoint Detection and Response (EDR) LT-5 Centralize security log management and analysis ASD37-27 Outbound data loss prevention (Very Good) ASD37-28 Continuous incident detection and response (Excellent) ASD37-29 Host-based IDS/IPS (Very Good) ASD37-30 Endpoint detection and response (Very Good) ASD37-32 Network-based IDS/IPS (Limited) ASD37-33 Capture network traffic (Limited) 3.11.2e Threat Hunting 3.11.3e Advanced Automation and Analytics Capabilities 3.14.2e Monitor Organizational Systems with Specialized Capabilities 3.14.3e Include Systems in Scope of Enhanced Requirements or Segregate into Purpose-Specific Networks 3.4.2e Automated Detection and Remediation of Unauthorized Software 3.6.1e Establish Security Operations Center (SOC) SOC2-CC4.1 CC4.1 Ongoing and separate evaluations of control (COSO principle 16) SOC2-CC6.6 CC6.6 Protection against threats from outside the system boundary SOC2-CC7.1 CC7.1 Detecting configuration changes and new vulnerabilities SOC2-CC7.2 CC7.2 Monitoring system components for anomalies SOC2-CC7.3 CC7.3 Evaluating security events to identify incidents SEC04-BP01 Configure service and application logging SEC04-BP03 Correlate and enrich security alerts SEC04-BP04 Initiate remediation for non-compliant resources SEC05-BP03 Implement inspection-based protection C5-COS-01 Technical safeguards C5-COS-03 Monitoring of connections in the Cloud Service Provider's network C5-OPS-13 Logging and Monitoring - Identification of Events 9.1 Monitoring, measurement, analysis and evaluation A.6.2.6 AI system operation and monitoring A.6.2.8 AI system recording of event logs DODZT-2.7 Endpoint and Extended Detection and Response DODZT-7.4 User and Entity Behavior Analytics 5.7.1 Monitoring, measurement, analysis and evaluation 6.9.4 Logging and monitoring 3(c)(ii)(A) Sec. 3(c)(ii)(A) (now 3(a)(ii)(A)) Provide CISA the EDR and SOC data the concept of operations requires 3(c)(v) Sec. 3(c)(v) (now 3(a)(v)) Enroll EDR endpoints in CISA's Persistent Access Capability E8-APP-ML3 Application Control (ML3) EUAI-Art.72 Post-market monitoring by providers and post-market monitoring plan for high-risk AI systems 9.1 Monitoring, measurement, analysis and evaluation 8.16 Monitoring activities 8.16 Monitoring activities NISTSP115-8 Operational Considerations - Tools, Reporting Templates, ISMS Integration, Annex Material SI-4 SI-4 System Monitoring SI-4 SI-4 System Monitoring SI-4 SI-4 System Monitoring Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected .
Other controls in SI - System and Information Integrity You are reading one control. How much of NIST SP 800-53 Rev 5 have you already done? NIST SP 800-53 Rev 5 NIST800-SI-4 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of NIST SP 800-53 Rev 5 your existing evidence covers. Hold ISO 27001:2022 and 163 of 1014 NIST SP 800-53 Rev 5 controls already carry evidence.
Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 342 were rejected on the ISO 27001:2022 pair alone.
Query this from an agent The graph holds this control, the 153 it maps to, and the evidence behind each claim, over MCP and REST.