DKDavid Koran& Associates
Home The CMMC Guide Part III · System and Information Integrity SI.L2-3.14.6
The CMMC Guide · System and Information Integrity Family

SI.L2-3.14.6  Monitor for Attacks

Monitor organizational systems, including inbound and outbound communications traffic, to detect attacks and indicators of potential attacks.

Family
System and Information IntegritySI, 7 requirements
Point Value
5Highest weight in the methodology
POA&M Eligible
NoCannot remain open at assessment
Objectives
ThreePer NIST SP 800-171A

1Overview

SI.L2-3.14.6 requires monitoring the system for attacks, including the traffic at its edges. It requires that organizational systems, including inbound and outbound communications traffic, be monitored to detect attacks and indicators of potential attacks, so that both the systems and the traffic crossing their boundaries are watched for signs of compromise. It is a five-point requirement that cannot be deferred on a plan of action.

Attacks leave signs, unusual system behavior, anomalous traffic, indicators that something is wrong, but only if something is watching for them. This control requires monitoring across three fronts: the system itself, its inbound traffic, and its outbound traffic. Inbound monitoring catches attacks arriving; outbound monitoring catches the signs of a compromise already inside, such as data leaving or systems communicating with attacker infrastructure. Its five-point weight reflects that undetected attacks proceed unopposed. The three assessment objectives are monitoring the system, inbound traffic, and outbound traffic.

The requirement · NIST SP 800-171 Rev 2, 3.14.6

Monitor organizational systems, including inbound and outbound communications traffic, to detect attacks and indicators of potential attacks.

The requirement names monitoring of the system and of both inbound and outbound traffic, to detect attacks and indicators of potential attacks. The three assessment objectives correspond to these: the system is monitored, inbound traffic is monitored, and outbound traffic is monitored, each to detect attacks and their indicators. Watching all three provides the visibility needed to notice an attack arriving, in progress, or exfiltrating.

2The Assessment Objectives

NIST SP 800-171A decomposes 3.14.6 into three objectives: monitor the system, inbound traffic, and outbound traffic.

[a]

The system is monitored to detect attacks and indicators of potential attacks. System behavior is watched for signs of compromise.

MeetsThe system is monitored to detect attacks and their indicators.
FailsSystem behavior is not monitored for attack indicators.
[b]

Inbound communications traffic is monitored to detect attacks and indicators of potential attacks. Incoming traffic is watched.

MeetsInbound traffic is monitored to detect attacks and their indicators.
FailsInbound traffic is not monitored.
[c]

Outbound communications traffic is monitored to detect attacks and indicators of potential attacks. Outgoing traffic is watched.

MeetsOutbound traffic is monitored to detect attacks and their indicators.
FailsOutbound traffic is not monitored.

The three objectives are monitoring the system, inbound, and outbound traffic. The common gap is at objective [c], outbound monitoring, which is often neglected in favor of watching what comes in, even though outbound signs reveal a compromise already inside. The assessor looks for monitoring across all three.

3Failure Patterns

The failures are about attacks that proceed unseen.

Inbound watched, outbound ignored

Monitoring only incoming traffic misses the signs of an active compromise, such as data exfiltration or command-and-control traffic leaving. Outbound monitoring reveals those.

Traffic watched, system not

Monitoring the network but not system behavior misses on-host attack indicators. The system itself has to be monitored too.

Monitoring not reviewed

Monitoring that generates alerts no one reviews detects nothing in practice. The monitoring has to be acted on to detect attacks.

The common root
This control fails when monitoring faces only outward. Watching for attacks arriving is natural, but a compromise already inside shows itself in system behavior and outbound traffic, so inbound-only monitoring misses the attack in progress. Monitoring the system and both traffic directions is what makes the compromise visible.

4Ownership

This is a security and IT-owned control tied to monitoring and detection.

RoleResponsibility for this control
Security and ITMonitors the system and inbound and outbound traffic for attacks. Owns the monitoring evidence.
Security or compliance leadConfirms monitoring covers the system and both traffic directions and is reviewed.
Program leadReviews detection output and retains the records.
See also: This control works with the boundary monitoring of SC.L2-3.13.1, the advisory response of SI.L2-3.14.3, and the audit and accountability family.

5Tooling

The control is delivered by system and network monitoring for attack detection.

ObjectiveToolingWhat it provides
[a]Host monitoring, EDR, SIEMSystem monitored for attack indicators.
[b]IDS/IPS, inbound traffic analysisInbound traffic monitored.
[c]Outbound traffic and exfiltration monitoringOutbound traffic monitored.

The caveat is that monitoring has to cover the system and both traffic directions and be reviewed. Inbound-only monitoring, or monitoring no one acts on, leaves attacks undetected. The assessor examines all three, so system, inbound, and outbound monitoring have to hold.

6Evidence

The satisfied version of 3.14.6 shows monitoring across system and both traffic directions.

EvidenceWhat it demonstrates
System monitoring configurationObjective [a]. System monitored for attacks.
Inbound and outbound monitoringObjectives [b], [c]. Both traffic directions monitored.

The evidence should show the system and both inbound and outbound traffic monitored to detect attacks and their indicators. The system monitoring configuration together with the inbound and outbound monitoring is the clearest demonstration, and because this control cannot sit on a plan of action, the monitoring has to be real at the time of assessment.

A compromise inside shows itself in what leaves

Inbound-only monitoring misses the active compromise revealed by system behavior and outbound traffic, so this five-point control asks that the system and both traffic directions be monitored. Building that monitoring is part of the onsite readiness work this practice does, and it is one of the controls that must be met rather than deferred.

Start CMMC Readiness or call 802-335-2662

7Sources

  1. NIST Special Publication 800-171 Rev 2, Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations, requirement 3.14.6. csrc.nist.gov
  2. NIST Special Publication 800-171A, Assessing Security Requirements for Controlled Unclassified Information, assessment objectives 3.14.6[a] through 3.14.6[c]. csrc.nist.gov
  3. 32 CFR 170.24, CMMC Scoring Methodology, listing SI.L2-3.14.6 among the five-point derived security requirements. ecfr.gov
← Previous in System and Information Integrity
SI.L2-3.14.5 · Scan for Malicious Code
Next in System and Information Integrity →
SI.L2-3.14.7 · Identify Unauthorized Use
About the Author
David W. Koran is a CyberAB Registered Practitioner Advanced and the author of The CMMC Decision, now in its second edition. He works onsite with defense contractors and their counsel, from the first leadership briefing through the pre-assessment review. Reach him at 802-335-2662 or dkoran@davidkoran.com.
Entry SI.L2-3.14.6 · Edition 2026.1 · Last reviewed July 12, 2026