>myctrl.tools
GitHub

SI-4(7)Automated Response To Suspicious Events

>Control Description

a. Notify [Assignment: organization-defined incident response personnel (identified by name and/or by role)] of detected suspicious events; and b. Take the following actions upon detection: [Assignment: organization-defined least-disruptive actions to terminate suspicious events].

>Supplemental Guidance

Least-disruptive actions include initiating requests for human responses.