Control Objectives: Monitoring and measurement
No control objectives match the current filters.
Adhere to operating procedures as defined in the Standard Operating Procedures Manual.
SNow
Classification: PreventiveState: Published
Adhere to operating procedures as defined in the Standard Operating Procedures Manual.
Alert interested personnel when suspicious activity is detected by an Intrusion Detection System or Intrusion Prevention System.
SNow
Classification: DetectiveState: Published
Alert interested personnel when suspicious activity is detected by an Intrusion Detection System or Intrusion Prevention System.
Analyze system audit reports and determine the need to perform more tests.
SNow
Classification: DetectiveState: Published
Analyze system audit reports and determine the need to perform more tests.
Archive the audit trail in accordance with compliance requirements.
SNow
Classification: PreventiveState: Published
Archive the audit trail in accordance with compliance requirements.
Assess customer satisfaction.
SNow
Classification: DetectiveState: Published
Assess customer satisfaction.
Assign penetration testing to a qualified internal resource or external third party.
SNow
Classification: PreventiveState: Published
Assign penetration testing to a qualified internal resource or external third party.
Assign vulnerability scanning to a qualified internal resource or external third party.
SNow
Classification: DetectiveState: Published
Assign vulnerability scanning to a qualified internal resource or external third party.
Automate the continuous monitoring of Configuration Management, as necessary.
SNow
Classification: DetectiveState: Published
Automate the continuous monitoring of Configuration Management, as necessary.
Back up audit trails according to backup procedures.
SNow
Classification: PreventiveState: Published
Back up audit trails according to backup procedures.
Back up logs according to backup procedures.
SNow
Classification: PreventiveState: Published
Back up logs according to backup procedures.
Centralize network time servers to as few as practical.
SNow
Classification: PreventiveState: Published
Centralize network time servers to as few as practical.
Compare system performance metrics to organizational standards and industry benchmarks.
SNow
Classification: DetectiveState: Published
Compare system performance metrics to organizational standards and industry benchmarks.
Copy logs from all predefined hosts onto a log management infrastructure.
SNow
Classification: PreventiveState: Published
Copy logs from all predefined hosts onto a log management infrastructure.
Correct vulnerabilities and repeat penetration testing.
SNow
Classification: DetectiveState: Published
Correct vulnerabilities and repeat penetration testing.
Correct vulnerabilities and repeat vulnerability scanning.
SNow
Classification: DetectiveState: Published
Correct vulnerabilities and repeat vulnerability scanning.
Create a plan of action to correct control deficiencies identified in an audit.
SNow
Classification: DetectiveState: Published
Create a plan of action to correct control deficiencies identified in an audit.
Create specific test plans to test each system component.
SNow
Classification: PreventiveState: Published
Create specific test plans to test each system component.
Define the frequency to capture and log events.
SNow
Classification: PreventiveState: Published
Define the frequency to capture and log events.
Deny access to restricted data or restricted information when an individual is terminated.
SNow
Classification: CorrectiveState: Published
Deny access to restricted data or restricted information when an individual is terminated.
Detect unauthorized access to systems.
SNow
Classification: DetectiveState: Published
Detect unauthorized access to systems.
Determine if honeypots should be installed, and if so, where the honeypots should be placed.
SNow
Classification: DetectiveState: Published
Determine if honeypots should be installed, and if so, where the honeypots should be placed.
Determine the appropriate assessment method for each testing process in the test plan.
SNow
Classification: PreventiveState: Published
Determine the appropriate assessment method for each testing process in the test plan.
Determine the effectiveness of risk control measures.
SNow
Classification: DetectiveState: Published
Determine the effectiveness of risk control measures.
Distribute the reviews of audit reports to organizational management.
SNow
Classification: DetectiveState: Published
Distribute the reviews of audit reports to organizational management.
Document the event information to be logged in the event information log specification.
SNow
Classification: PreventiveState: Published
Document the event information to be logged in the event information log specification.
Document validated testing processes in the testing procedures.
SNow
Classification: PreventiveState: Published
Document validated testing processes in the testing procedures.
Enable and configure logging on all network access controls.
SNow
Classification: PreventiveState: Published
Enable and configure logging on all network access controls.
Enable logging for all systems that meet a traceability criteria.
SNow
Classification: DetectiveState: Published
Enable logging for all systems that meet a traceability criteria.
Enable monitoring and logging operations on all assets that meet the organizational criteria to maintain event logs.
SNow
Classification: PreventiveState: Published
Enable monitoring and logging operations on all assets that meet the organizational criteria to maintain event logs.
Encrypt files and move them to a secure file server when a user account is disabled.
SNow
Classification: PreventiveState: Published
Encrypt files and move them to a secure file server when a user account is disabled.
Escalate the report when the software configuration is updated absent authorization.
SNow
Classification: DetectiveState: Published
Escalate the report when the software configuration is updated absent authorization.
Establish and maintain a Software Change Management metrics program.
SNow
Classification: PreventiveState: Published
Establish and maintain a Software Change Management metrics program.
Establish and maintain a System Security Plan.
SNow
Classification: PreventiveState: Published
Establish and maintain a System Security Plan.
Establish and maintain a compliance monitoring policy.
SNow
Classification: PreventiveState: Published
Establish and maintain a compliance monitoring policy.
Children (6)
- Establish and maintain a log management program.
- Establish and maintain a metrics policy.
- Establish and maintain a technical measurement metrics polic...
- Establish and maintain an approach for compliance monitoring...
- Monitor personnel and third parties for compliance to the or...
- Provide transactional walkthrough procedures for external au...
Establish and maintain a continuous monitoring for Configuration Management program.
SNow
Classification: DetectiveState: Published
Establish and maintain a continuous monitoring for Configuration Management program.
Establish and maintain a log management program.
SNow
Classification: PreventiveState: Published
Establish and maintain a log management program.
Children (7)
- Archive the audit trail in accordance with compliance requir...
- Back up audit trails according to backup procedures.
- Back up logs according to backup procedures.
- Copy logs from all predefined hosts onto a log management in...
- Limit access to audit trails to a need to know basis.
- Limit access to logs to a need to know basis.
- Protect logs from unauthorized activity.
Establish and maintain a metrics policy.
SNow
Classification: PreventiveState: Published
Establish and maintain a metrics policy.
Establish and maintain a penetration test program.
SNow
Classification: PreventiveState: Published
Establish and maintain a penetration test program.
Children (9)
- Retain penetration test remediation action records according...
- Test the system for Cross-Site Request Forgery.
- Test the system for broken access controls.
- Test the system for broken authentication and session manage...
- Test the system for buffer overflows.
- Test the system for cross-site scripting attacks.
- Test the system for injection flaws.
- Test the system for insecure communications.
- Test the system for insecure configuration management.
Establish and maintain a policies and controls metrics program.
SNow
Classification: PreventiveState: Published
Establish and maintain a policies and controls metrics program.
Establish and maintain a risk monitoring program.
SNow
Classification: PreventiveState: Published
Establish and maintain a risk monitoring program.
Children (8)
- Analyze system audit reports and determine the need to perfo...
- Determine the appropriate assessment method for each testing...
- Establish and maintain a System Security Plan.
- Monitor continuously for threats.
- Monitor devices continuously for conformance with production...
- Monitor for new vulnerabilities.
- Test compliance controls for proper functionality.
- Validate all testing assumptions in the test plans.
Establish and maintain a security test program.
SNow
Classification: PreventiveState: Published
Establish and maintain a security test program.
Establish and maintain a technical measurement metrics policy.
SNow
Classification: PreventiveState: Published
Establish and maintain a technical measurement metrics policy.
Establish and maintain a vulnerability analysis program.
SNow
Classification: PreventiveState: Published
Establish and maintain a vulnerability analysis program.
Establish and maintain an Information Security metrics program.
SNow
Classification: PreventiveState: Published
Establish and maintain an Information Security metrics program.
Establish and maintain an approach for compliance monitoring.
SNow
Classification: PreventiveState: Published
Establish and maintain an approach for compliance monitoring.
Establish and maintain an incident management and vulnerability management metrics program.
SNow
Classification: PreventiveState: Published
Establish and maintain an incident management and vulnerability management metrics program.
Establish and maintain event logging procedures.
SNow
Classification: DetectiveState: Published
Establish and maintain event logging procedures.
Establish and maintain intrusion management operations.
SNow
Classification: PreventiveState: Published
Establish and maintain intrusion management operations.
Children (5)
- Determine if honeypots should be installed, and if so, where...
- Install and maintain an Intrusion Detection System and/or In...
- Monitor systems for inappropriate usage and other security v...
- Protect each person's right to privacy and civil liberties d...
- Update the intrusion detection capabilities and the incident...
Establish and maintain logging and monitoring operations.
SNow
Classification: DetectiveState: Published
Establish and maintain logging and monitoring operations.
Children (9)
- Assess customer satisfaction.
- Distribute the reviews of audit reports to organizational ma...
- Enable monitoring and logging operations on all assets that ...
- Establish and maintain a continuous monitoring for Configura...
- Establish and maintain intrusion management operations.
- Include a standard to collect and interpret event logs in th...
- Monitor and evaluate system performance.
- Monitor and evaluate user account activity.
- Operationalize key monitoring and logging concepts to ensure...
Implement automated audit tools.
SNow
Classification: PreventiveState: Published
Implement automated audit tools.
Implement file integrity monitoring.
SNow
Classification: DetectiveState: Published
Implement file integrity monitoring.
Include a standard to collect and interpret event logs in the event logging procedures.
SNow
Classification: PreventiveState: Published
Include a standard to collect and interpret event logs in the event logging procedures.
Install and maintain an Intrusion Detection System and/or Intrusion Prevention System.
SNow
Classification: PreventiveState: Published
Install and maintain an Intrusion Detection System and/or Intrusion Prevention System.
Limit access to audit trails to a need to know basis.
SNow
Classification: PreventiveState: Published
Limit access to audit trails to a need to know basis.
Limit access to logs to a need to know basis.
SNow
Classification: PreventiveState: Published
Limit access to logs to a need to know basis.
Monitor and evaluate system performance.
SNow
Classification: DetectiveState: Published
Monitor and evaluate system performance.
Monitor and evaluate user account activity.
SNow
Classification: DetectiveState: Published
Monitor and evaluate user account activity.
Monitor compliance with the Quality Control system.
SNow
Classification: PreventiveState: Published
Monitor compliance with the Quality Control system.
Monitor continuously for threats.
SNow
Classification: PreventiveState: Published
Monitor continuously for threats.
Monitor devices continuously for conformance with production specifications.
SNow
Classification: DetectiveState: Published
Monitor devices continuously for conformance with production specifications.
Monitor for and report when a software configuration is updated.
SNow
Classification: DetectiveState: Published
Monitor for and report when a software configuration is updated.
Monitor for firmware updates absent authorization.
SNow
Classification: DetectiveState: Published
Monitor for firmware updates absent authorization.
Monitor for new vulnerabilities.
SNow
Classification: PreventiveState: Published
Monitor for new vulnerabilities.
Monitor for software configurations updates absent authorization.
SNow
Classification: PreventiveState: Published
Monitor for software configurations updates absent authorization.
Monitor for when documents are being updated absent authorization.
SNow
Classification: PreventiveState: Published
Monitor for when documents are being updated absent authorization.
Monitor personnel and third parties for compliance to the organizational compliance framework.
SNow
Classification: DetectiveState: Published
Monitor personnel and third parties for compliance to the organizational compliance framework.
Monitor systems for Denial of Service attacks.
SNow
Classification: DetectiveState: Published
Monitor systems for Denial of Service attacks.
Monitor systems for access to restricted data or restricted information.
SNow
Classification: DetectiveState: Published
Monitor systems for access to restricted data or restricted information.
Monitor systems for blended attacks and multiple component incidents.
SNow
Classification: DetectiveState: Published
Monitor systems for blended attacks and multiple component incidents.
Monitor systems for inappropriate usage and other security violations.
SNow
Classification: DetectiveState: Published
Monitor systems for inappropriate usage and other security violations.
Monitor systems for unauthorized mobile code.
SNow
Classification: PreventiveState: Published
Monitor systems for unauthorized mobile code.
Monitor the activities to correct control deficiencies identified in an audit.
SNow
Classification: DetectiveState: Published
Monitor the activities to correct control deficiencies identified in an audit.
Monitor the usage and capacity of critical IT assets.
SNow
Classification: DetectiveState: Published
Monitor the usage and capacity of critical IT assets.
Monitoring and measurement
SNow
Classification: IT Impact ZoneState: Published
Monitoring and measurement
Parent
Children (8)
- Compare system performance metrics to organizational standar...
- Create a plan of action to correct control deficiencies iden...
- Establish and maintain a compliance monitoring policy.
- Establish and maintain a risk monitoring program.
- Establish and maintain a security test program.
- Establish and maintain logging and monitoring operations.
- Monitor the activities to correct control deficiencies ident...
- Report compliance monitoring statistics to the Board of Dire...
Notify the interested personnel and affected parties after the failure of an automated security test.
SNow
Classification: CorrectiveState: Published
Notify the interested personnel and affected parties after the failure of an automated security test.
Notify the interested personnel and affected parties before the storage unit will reach maximum capacity.
SNow
Classification: DetectiveState: Published
Notify the interested personnel and affected parties before the storage unit will reach maximum capacity.
Operationalize key monitoring and logging concepts to ensure the audit trails capture sufficient information.
SNow
Classification: DetectiveState: Published
Operationalize key monitoring and logging concepts to ensure the audit trails capture sufficient information.
Perform application-layer penetration testing on all systems, as necessary.
SNow
Classification: DetectiveState: Published
Perform application-layer penetration testing on all systems, as necessary.
Perform internal vulnerability scans on the organization's systems.
SNow
Classification: DetectiveState: Published
Perform internal vulnerability scans on the organization's systems.
Perform network-layer penetration testing on all systems, as necessary.
SNow
Classification: DetectiveState: Published
Perform network-layer penetration testing on all systems, as necessary.
Perform penetration testing on a regular basis.
SNow
Classification: DetectiveState: Published
Perform penetration testing on a regular basis.
Children (8)
- Assign penetration testing to a qualified internal resource ...
- Assign vulnerability scanning to a qualified internal resour...
- Correct vulnerabilities and repeat penetration testing.
- Correct vulnerabilities and repeat vulnerability scanning.
- Perform application-layer penetration testing on all systems...
- Perform internal vulnerability scans on the organization's s...
- Perform network-layer penetration testing on all systems, as...
- Scan the network for Wireless Access Points.
Perform vulnerability scanning on a regular basis.
SNow
Classification: DetectiveState: Published
Perform vulnerability scanning on a regular basis.
Protect each person's right to privacy and civil liberties during intrusion management operations.
SNow
Classification: PreventiveState: Published
Protect each person's right to privacy and civil liberties during intrusion management operations.
Protect logs from unauthorized activity.
SNow
Classification: PreventiveState: Published
Protect logs from unauthorized activity.
Protect the event logs from failure.
SNow
Classification: PreventiveState: Published
Protect the event logs from failure.
Provide transactional walkthrough procedures for external auditors.
SNow
Classification: PreventiveState: Published
Provide transactional walkthrough procedures for external auditors.
Recommend mitigation techniques based on penetration test results.
SNow
Classification: CorrectiveState: Published
Recommend mitigation techniques based on penetration test results.
Report compliance monitoring statistics to the Board of Directors and other key stakeholders, as necessary.
SNow
Classification: CorrectiveState: Published
Report compliance monitoring statistics to the Board of Directors and other key stakeholders, as necessary.
Report on the mean time from patch availability to patch installation.
SNow
Classification: DetectiveState: Published
Report on the mean time from patch availability to patch installation.
Retain penetration test remediation action records according to internal policy.
SNow
Classification: PreventiveState: Published
Retain penetration test remediation action records according to internal policy.
Review accounts and access rights when notified of personnel status changes.
SNow
Classification: CorrectiveState: Published
Review accounts and access rights when notified of personnel status changes.
Review and terminate accounts or terminate access rights when notified than an individual is terminated.
SNow
Classification: CorrectiveState: Published
Review and terminate accounts or terminate access rights when notified than an individual is terminated.
Review and update the list of auditable events in the event logging procedures.
SNow
Classification: PreventiveState: Published
Review and update the list of auditable events in the event logging procedures.
Review event logs, Intrusion Detection System reports, security incident tracking reports, and other security logs regularly.
SNow
Classification: DetectiveState: Published
Review event logs, Intrusion Detection System reports, security incident tracking reports, and other security logs regularly.
Revoke asset access when an individual is terminated.
SNow
Classification: CorrectiveState: Published
Revoke asset access when an individual is terminated.
Scan the network for Wireless Access Points.
SNow
Classification: DetectiveState: Published
Scan the network for Wireless Access Points.
Scan wireless networks for rogue devices.
SNow
Classification: DetectiveState: Published
Scan wireless networks for rogue devices.
Supply each in scope asset with audit reduction tool and report generation capabilities to support after-the-fact investigations without altering the event logs.
SNow
Classification: PreventiveState: Published
Supply each in scope asset with audit reduction tool and report generation capabilities to support after-the-fact investigations without altering the event logs.
Synchronize system clocks to an accurate and universal time source on all devices that have logging enabled.
SNow
Classification: PreventiveState: Published
Synchronize system clocks to an accurate and universal time source on all devices that have logging enabled.
Test compliance controls for proper functionality.
SNow
Classification: DetectiveState: Published
Test compliance controls for proper functionality.
Test the system for Cross-Site Request Forgery.
SNow
Classification: DetectiveState: Published
Test the system for Cross-Site Request Forgery.
Test the system for broken access controls.
SNow
Classification: DetectiveState: Published
Test the system for broken access controls.
Test the system for broken authentication and session management.
SNow
Classification: DetectiveState: Published
Test the system for broken authentication and session management.
Test the system for buffer overflows.
SNow
Classification: DetectiveState: Published
Test the system for buffer overflows.
Test the system for cross-site scripting attacks.
SNow
Classification: DetectiveState: Published
Test the system for cross-site scripting attacks.
Test the system for injection flaws.
SNow
Classification: DetectiveState: Published
Test the system for injection flaws.
Test the system for insecure communications.
SNow
Classification: DetectiveState: Published
Test the system for insecure communications.
Test the system for insecure configuration management.
SNow
Classification: DetectiveState: Published
Test the system for insecure configuration management.
Test the system for insecure cryptographic storage.
SNow
Classification: DetectiveState: Published
Test the system for insecure cryptographic storage.
Test the system for proper error handling.
SNow
Classification: DetectiveState: Published
Test the system for proper error handling.
The manufacturing system and/or network should be covered by the OT Security Monitoring (industrial Intrusion Detection System - IIDS) service according to OT Monitoring Scope requirements defined within the DIA OT CS Security & Operations SOP.
SNow
Classification: DetectState: Published
Update the intrusion detection capabilities and the incident response capabilities regularly.
SNow
Classification: PreventiveState: Published
Update the intrusion detection capabilities and the incident response capabilities regularly.
Update the vulnerability scanners' vulnerability list.
SNow
Classification: CorrectiveState: Published
Update the vulnerability scanners' vulnerability list.
Use automated mechanisms to compare new vulnerability test results with past vulnerability test results.
SNow
Classification: DetectiveState: Published
Use automated mechanisms to compare new vulnerability test results with past vulnerability test results.
Validate all testing assumptions in the test plans.
SNow
Classification: DetectiveState: Published
Validate all testing assumptions in the test plans.