SI-4(7)—Information System Monitoring
PBMM (P2)
Secret (P2)
Operational
>Control Description
INFORMATION SYSTEM MONITORING | AUTOMATED RESPONSE TO SUSPICIOUS EVENTS The information system notifies ⚙organization-defined incident response personnel (identified by name and/or by role) of detected suspicious events and takes ⚙organization-defined least-disruptive actions to terminate suspicious events.
>Supplemental Guidance
Least-disruptive actions may include, for example, initiating requests for human responses.
>Tailoring Guidance
Control enhancements (7) and (12) expand on control enhancement (2).
>Profile-Specific Parameters
(7) list [list of roles], list [list of termination actions]
Ask AI
Configure your API key to use AI features.