DKDavid Koran& Associates
Home The CMMC Guide Part III · System and Information Integrity SI.L2-3.14.3
The CMMC Guide · System and Information Integrity Family

SI.L2-3.14.3  Monitor Security Alerts and Advisories

Monitor system security alerts and advisories and take action in response.

Family
System and Information IntegritySI, 7 requirements
Point Value
5Highest weight in the methodology
POA&M Eligible
NoCannot remain open at assessment
Objectives
ThreePer NIST SP 800-171A

1Overview

SI.L2-3.14.3 requires that the organization watch external threat intelligence and act on it. It requires that system security alerts and advisories be monitored and that action be taken in response, so that warnings about emerging threats reach the organization and produce a response. It is a five-point requirement that cannot be deferred on a plan of action.

The security community continuously publishes alerts and advisories about new vulnerabilities and threats, and these warnings are useful only if the organization sees them and acts. This control requires monitoring those security alerts and advisories and taking action in response, with the response actions identified in advance so that a warning leads to a defined reaction rather than being noted and forgotten. Its five-point weight reflects that ignored advisories leave known, publicized threats unaddressed. The three assessment objectives are identifying response actions, monitoring the alerts, and taking action.

The requirement · NIST SP 800-171 Rev 2, 3.14.3

Monitor system security alerts and advisories and take action in response.

The requirement pairs monitoring with response. The assessment objectives make explicit that response actions are identified, the alerts and advisories are monitored, and actions are taken in response. Identifying response actions ahead of time means the organization knows how it will react; monitoring brings the warnings in; taking action closes the loop. Together they turn external threat intelligence into concrete defensive action.

2The Assessment Objectives

NIST SP 800-171A decomposes 3.14.3 into three objectives: identify response actions, monitor alerts, and take action.

[a]

Response actions to system security alerts and advisories are identified. How the organization will respond is defined.

MeetsResponse actions to alerts and advisories are identified.
FailsNo response actions are defined.
[b]

System security alerts and advisories are monitored. The warnings are watched.

MeetsSecurity alerts and advisories are monitored.
FailsAlerts and advisories are not monitored.
[c]

Actions in response to system security alerts and advisories are taken. The organization acts on the warnings.

MeetsActions are taken in response to alerts and advisories.
FailsAlerts are monitored but not acted on.

The three objectives are identify responses, monitor, and act. The common gap is at objective [c], where advisories are monitored but no action follows, so warnings are seen and ignored. The assessor looks for identified responses, monitoring, and action taken.

3Failure Patterns

The failures are about advisories seen but not acted on.

Monitoring without action

Receiving alerts and advisories without responding leaves the warned-of threats unaddressed. Taking identified actions closes the loop.

No monitoring of advisories

Where security alerts and advisories are not monitored, the organization learns of threats late or not at all. Monitoring brings the warnings in.

No defined response actions

Without response actions identified in advance, reaction to an advisory is ad hoc and slow. Defining the responses makes the reaction reliable.

The common root
This control fails in the gap between awareness and action. Advisories are easy to receive and note, but acting on them takes effort and coordination, so warnings pile up unaddressed. Identifying responses in advance and taking action is what converts threat intelligence into defense.

4Ownership

This is a security-owned control.

RoleResponsibility for this control
Security or compliance leadIdentifies response actions, monitors alerts and advisories, and ensures action is taken. Owns the evidence.
IT and system administratorCarries out the response actions on systems.
Program leadConfirms advisories are monitored and acted on, and retains records.
See also: This control feeds the flaw remediation of SI.L2-3.14.1 and connects to the vulnerability scanning of RA.L2-3.11.2.

5Tooling

The control is delivered by advisory monitoring and a defined response process.

ObjectivesToolingWhat it provides
[a]Defined response actionsHow the organization will react to advisories.
[b]Advisory feeds and subscriptionsMonitored security alerts and advisories.
[c]Response execution and trackingActions taken on the warnings.

The caveat is that action has to actually follow the monitoring. Subscribing to advisory feeds without a response process, or defining responses that are never executed, leaves objectives unmet. The assessor examines all three, so identification, monitoring, and action have to hold.

6Evidence

The satisfied version of 3.14.3 shows advisories monitored and acted on.

EvidenceWhat it demonstrates
Defined response actionsObjective [a]. How the organization responds.
Advisory monitoringObjective [b]. Alerts and advisories monitored.
Response recordsObjective [c]. Actions taken in response.

The evidence should show identified response actions, monitored alerts and advisories, and records of actions taken. The defined responses together with the monitoring and response records are the clearest demonstration, and because this control cannot sit on a plan of action, the practice has to be real at the time of assessment.

An ignored advisory is a known threat left open

Warnings about emerging threats are useful only if acted on, so this five-point control asks that alerts and advisories be monitored and responses taken. Building a monitor-and-respond process is part of the onsite readiness work this practice does, and it is one of the controls that must be met rather than deferred.

Start CMMC Readiness or call 802-335-2662

7Sources

  1. NIST Special Publication 800-171 Rev 2, Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations, requirement 3.14.3. csrc.nist.gov
  2. NIST Special Publication 800-171A, Assessing Security Requirements for Controlled Unclassified Information, assessment objectives 3.14.3[a] through 3.14.3[c]. csrc.nist.gov
  3. 32 CFR 170.24, CMMC Scoring Methodology, listing SI.L2-3.14.3 among the five-point basic security requirements. ecfr.gov
← Previous in System and Information Integrity
SI.L2-3.14.2 · Malicious Code Protection
Next in System and Information Integrity →
SI.L2-3.14.4 · Update Malicious Code Protection
About the Author
David W. Koran is a CyberAB Registered Practitioner Advanced and the author of The CMMC Decision, now in its second edition. He works onsite with defense contractors and their counsel, from the first leadership briefing through the pre-assessment review. Reach him at 802-335-2662 or dkoran@davidkoran.com.
Entry SI.L2-3.14.3 · Edition 2026.1 · Last reviewed July 12, 2026