SI-05 Security Alerts And Advisories

System and Information Integrity

Low Moderate High

Description

The organization receives information system security alerts/advisories on a regular basis, issues alerts/advisories to appropriate personnel, and takes appropriate actions in response.\n

Supplemental Guidance

The organization documents the types of actions to be taken in response to security alerts/advisories. The organization also maintains contact with special interest groups (e.g., information security forums) that: (i) facilitate sharing of security-related information (e.g., threats, vulnerabilities, and latest security technologies); (ii) provide access to advice from security professionals; and (iii) improve knowledge of security best practices. NIST Special Publication 800-40 provides guidance on monitoring and distributing security alerts and advisories.\n

Enhancements

(1) The organization employs automated mechanisms to make security alert and advisory information available throughout the organization as needed.\n

Compliance Mappings

ISO 27001:2022

7.47.4(a)7.4(b)7.4(c)7.4(d)

ISO 27002:2022

5.7

NIST CSF 2.0

DEDE.AE-07ID.RA-02ID.RA-03ID.RA-08

SOC 2 TSC

CC3.2-POF6CC3.2-POF7CC6.6CC6.6-POF2CC9.2-POF13PI1.2-POF1PI1.2-POF2PI1.2-POF3

ISO 17799 (legacy)

6.1.710.4.1

COBIT 4.1 (legacy)

None.