1Overview
SI.L2-3.14.3 requires that the organization watch external threat intelligence and act on it. It requires that system security alerts and advisories be monitored and that action be taken in response, so that warnings about emerging threats reach the organization and produce a response. It is a five-point requirement that cannot be deferred on a plan of action.
The security community continuously publishes alerts and advisories about new vulnerabilities and threats, and these warnings are useful only if the organization sees them and acts. This control requires monitoring those security alerts and advisories and taking action in response, with the response actions identified in advance so that a warning leads to a defined reaction rather than being noted and forgotten. Its five-point weight reflects that ignored advisories leave known, publicized threats unaddressed. The three assessment objectives are identifying response actions, monitoring the alerts, and taking action.
Monitor system security alerts and advisories and take action in response.
The requirement pairs monitoring with response. The assessment objectives make explicit that response actions are identified, the alerts and advisories are monitored, and actions are taken in response. Identifying response actions ahead of time means the organization knows how it will react; monitoring brings the warnings in; taking action closes the loop. Together they turn external threat intelligence into concrete defensive action.
2The Assessment Objectives
NIST SP 800-171A decomposes 3.14.3 into three objectives: identify response actions, monitor alerts, and take action.
Response actions to system security alerts and advisories are identified. How the organization will respond is defined.
System security alerts and advisories are monitored. The warnings are watched.
Actions in response to system security alerts and advisories are taken. The organization acts on the warnings.
The three objectives are identify responses, monitor, and act. The common gap is at objective [c], where advisories are monitored but no action follows, so warnings are seen and ignored. The assessor looks for identified responses, monitoring, and action taken.
3Failure Patterns
The failures are about advisories seen but not acted on.
Monitoring without action
Receiving alerts and advisories without responding leaves the warned-of threats unaddressed. Taking identified actions closes the loop.
No monitoring of advisories
Where security alerts and advisories are not monitored, the organization learns of threats late or not at all. Monitoring brings the warnings in.
No defined response actions
Without response actions identified in advance, reaction to an advisory is ad hoc and slow. Defining the responses makes the reaction reliable.
4Ownership
This is a security-owned control.
| Role | Responsibility for this control |
|---|---|
| Security or compliance lead | Identifies response actions, monitors alerts and advisories, and ensures action is taken. Owns the evidence. |
| IT and system administrator | Carries out the response actions on systems. |
| Program lead | Confirms advisories are monitored and acted on, and retains records. |
5Tooling
The control is delivered by advisory monitoring and a defined response process.
| Objectives | Tooling | What it provides |
|---|---|---|
| [a] | Defined response actions | How the organization will react to advisories. |
| [b] | Advisory feeds and subscriptions | Monitored security alerts and advisories. |
| [c] | Response execution and tracking | Actions taken on the warnings. |
The caveat is that action has to actually follow the monitoring. Subscribing to advisory feeds without a response process, or defining responses that are never executed, leaves objectives unmet. The assessor examines all three, so identification, monitoring, and action have to hold.
6Evidence
The satisfied version of 3.14.3 shows advisories monitored and acted on.
| Evidence | What it demonstrates |
|---|---|
| Defined response actions | Objective [a]. How the organization responds. |
| Advisory monitoring | Objective [b]. Alerts and advisories monitored. |
| Response records | Objective [c]. Actions taken in response. |
The evidence should show identified response actions, monitored alerts and advisories, and records of actions taken. The defined responses together with the monitoring and response records are the clearest demonstration, and because this control cannot sit on a plan of action, the practice has to be real at the time of assessment.
An ignored advisory is a known threat left open
Warnings about emerging threats are useful only if acted on, so this five-point control asks that alerts and advisories be monitored and responses taken. Building a monitor-and-respond process is part of the onsite readiness work this practice does, and it is one of the controls that must be met rather than deferred.
Start CMMC Readiness or call 802-335-26627Sources
- NIST Special Publication 800-171 Rev 2, Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations, requirement 3.14.3. csrc.nist.gov
- NIST Special Publication 800-171A, Assessing Security Requirements for Controlled Unclassified Information, assessment objectives 3.14.3[a] through 3.14.3[c]. csrc.nist.gov
- 32 CFR 170.24, CMMC Scoring Methodology, listing SI.L2-3.14.3 among the five-point basic security requirements. ecfr.gov