1Overview
SI.L2-3.14.6 requires monitoring the system for attacks, including the traffic at its edges. It requires that organizational systems, including inbound and outbound communications traffic, be monitored to detect attacks and indicators of potential attacks, so that both the systems and the traffic crossing their boundaries are watched for signs of compromise. It is a five-point requirement that cannot be deferred on a plan of action.
Attacks leave signs, unusual system behavior, anomalous traffic, indicators that something is wrong, but only if something is watching for them. This control requires monitoring across three fronts: the system itself, its inbound traffic, and its outbound traffic. Inbound monitoring catches attacks arriving; outbound monitoring catches the signs of a compromise already inside, such as data leaving or systems communicating with attacker infrastructure. Its five-point weight reflects that undetected attacks proceed unopposed. The three assessment objectives are monitoring the system, inbound traffic, and outbound traffic.
Monitor organizational systems, including inbound and outbound communications traffic, to detect attacks and indicators of potential attacks.
The requirement names monitoring of the system and of both inbound and outbound traffic, to detect attacks and indicators of potential attacks. The three assessment objectives correspond to these: the system is monitored, inbound traffic is monitored, and outbound traffic is monitored, each to detect attacks and their indicators. Watching all three provides the visibility needed to notice an attack arriving, in progress, or exfiltrating.
2The Assessment Objectives
NIST SP 800-171A decomposes 3.14.6 into three objectives: monitor the system, inbound traffic, and outbound traffic.
The system is monitored to detect attacks and indicators of potential attacks. System behavior is watched for signs of compromise.
Inbound communications traffic is monitored to detect attacks and indicators of potential attacks. Incoming traffic is watched.
Outbound communications traffic is monitored to detect attacks and indicators of potential attacks. Outgoing traffic is watched.
The three objectives are monitoring the system, inbound, and outbound traffic. The common gap is at objective [c], outbound monitoring, which is often neglected in favor of watching what comes in, even though outbound signs reveal a compromise already inside. The assessor looks for monitoring across all three.
3Failure Patterns
The failures are about attacks that proceed unseen.
Inbound watched, outbound ignored
Monitoring only incoming traffic misses the signs of an active compromise, such as data exfiltration or command-and-control traffic leaving. Outbound monitoring reveals those.
Traffic watched, system not
Monitoring the network but not system behavior misses on-host attack indicators. The system itself has to be monitored too.
Monitoring not reviewed
Monitoring that generates alerts no one reviews detects nothing in practice. The monitoring has to be acted on to detect attacks.
4Ownership
This is a security and IT-owned control tied to monitoring and detection.
| Role | Responsibility for this control |
|---|---|
| Security and IT | Monitors the system and inbound and outbound traffic for attacks. Owns the monitoring evidence. |
| Security or compliance lead | Confirms monitoring covers the system and both traffic directions and is reviewed. |
| Program lead | Reviews detection output and retains the records. |
5Tooling
The control is delivered by system and network monitoring for attack detection.
| Objective | Tooling | What it provides |
|---|---|---|
| [a] | Host monitoring, EDR, SIEM | System monitored for attack indicators. |
| [b] | IDS/IPS, inbound traffic analysis | Inbound traffic monitored. |
| [c] | Outbound traffic and exfiltration monitoring | Outbound traffic monitored. |
The caveat is that monitoring has to cover the system and both traffic directions and be reviewed. Inbound-only monitoring, or monitoring no one acts on, leaves attacks undetected. The assessor examines all three, so system, inbound, and outbound monitoring have to hold.
6Evidence
The satisfied version of 3.14.6 shows monitoring across system and both traffic directions.
| Evidence | What it demonstrates |
|---|---|
| System monitoring configuration | Objective [a]. System monitored for attacks. |
| Inbound and outbound monitoring | Objectives [b], [c]. Both traffic directions monitored. |
The evidence should show the system and both inbound and outbound traffic monitored to detect attacks and their indicators. The system monitoring configuration together with the inbound and outbound monitoring is the clearest demonstration, and because this control cannot sit on a plan of action, the monitoring has to be real at the time of assessment.
A compromise inside shows itself in what leaves
Inbound-only monitoring misses the active compromise revealed by system behavior and outbound traffic, so this five-point control asks that the system and both traffic directions be monitored. Building that monitoring is part of the onsite readiness work this practice does, and it is one of the controls that must be met rather than deferred.
Start CMMC Readiness or call 802-335-26627Sources
- NIST Special Publication 800-171 Rev 2, Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations, requirement 3.14.6. csrc.nist.gov
- NIST Special Publication 800-171A, Assessing Security Requirements for Controlled Unclassified Information, assessment objectives 3.14.6[a] through 3.14.6[c]. csrc.nist.gov
- 32 CFR 170.24, CMMC Scoring Methodology, listing SI.L2-3.14.6 among the five-point derived security requirements. ecfr.gov