03.14.03: Security Alerts, Advisories, and Directives
Control Familly: System and Information Integrity
SPRS: N/A
Top Ten Failed Requirement: N/A
Supporting Publications:
SP 800-161 [33]
Referenced in: N/A
Control Type: N/A
CPCSC Level 2: 03.14.03
CMMC Level(s): N/A
Derived From: NIST SP 800-53r5
SI-05
a. Receive system security alerts, advisories, and directives from external organizations on an ongoing basis.
b. Generate and disseminate internal system security alerts, advisories, and directives, as necessary.
Discussion:
There are many publicly available sources of system security alerts and advisories. The Department of Homeland Security’s Cybersecurity and Infrastructure Security Agency (CISA), the National Security Agency (NSA), and the Federal Bureau of Investigation (FBI) generate security alerts and advisories to maintain situational awareness across the Federal Government and in nonfederal organizations. Software vendors, subscription services, and industry Information Sharing and Analysis Centers (ISACs) may also provide security alerts and advisories. Compliance with security directives is essential due to the critical nature of many of these directives and the potential immediate adverse effects on organizational operations and assets, individuals, other organizations, and the Nation should the directives not be implemented in a timely manner.Assessment Methods and Objectives
Examine [SELECT FROM: system and information integrity policy and procedures; procedures for security alerts, advisories, and directives; records of security alerts and advisories; system security plan; other relevant documents or records]
Interview [SELECT FROM: personnel with security alert and advisory responsibilities; personnel implementing, operating, maintaining, and using the system; personnel, organizational elements, or external organizations to whom alerts, advisories, and directives are to be disseminated; personnel with information security responsibilities; system administrators]
Test [SELECT FROM: processes for defining, receiving, generating, disseminating, and complying with security alerts, advisories, and directives; mechanisms for supporting or implementing security directives; mechanisms for supporting or implementing the definition, receipt, generation, and dissemination of security alerts, advisories, and directives]
NIST SP 800-171A r3 Determining Statements Determine if:
A.03.14.03.a: system security alerts, advisories, and directives from external organizations are received on an ongoing basis.
A.03.14.03.b[01]: internal security alerts, advisories, and directives are generated, as necessary.
A.03.14.03.b[02]: internal security alerts, advisories, and directives are disseminated, as necessary.
The Security Requirements
NIST SP 800-171r3 (USA) & ITSP.10.171 (Canada)
3.5. Identification and Authentication
3.12. Security Assessment and Monitoring
3.13. System and Communications Protection
3.14. System and Information Integrity
3.16. System and Services Acquisition
3.17. Supply Chain Risk Management
CMMC 3.0 - N/A
CPCSC - N/A