SI.L2-3.14.5[a] – Identify malware protection mechanisms.
This objective requires your organization to identify the tools, services, and strategies used to protect systems against malware, especially for systems that store, process, or transmit Controlled Unclassified Information (CUI).
SI.L2-3.14.1[c] – Determine if mechanisms to monitor systems for attacks and indicators of potential attacks are used.
This objective ensures your organization’s system monitoring tools and methods are not just documented, but actually operational, actively protecting systems handling Controlled Unclassified Information (CUI).
SI.L2-3.14.1[d] – Determine if mechanisms to monitor systems for attacks and indicators of potential attacks are enforced.
This objective ensures your organization not only uses monitoring tools for CUI systems, but also enforces monitoring as a non-optional, mandatory control—meaning monitoring cannot be disabled, bypassed, or left inactive without detection and escalation.
SI.L2-3.14.6[a] – Identify systems where updates for vulnerabilities and flaws must be installed.
This objective requires your organization to identify all systems and applications that need updates and patches to correct vulnerabilities or flaws—especially those that store, process, or transmit Controlled Unclassified Information (CUI).
SI.L2-3.14.4 – Monitor system security alerts and advisories and take action in response.
This control requires your organization to actively monitor trusted sources for security alerts and advisories—and respond appropriately when new threats, vulnerabilities, or patches affecting your systems (especially CUI systems) are announced.
SI.L2-3.14.7[b] – Examine documentation to confirm unauthorized use of organizational systems is identified.
This objective ensures your organization has formally documented how it detects unauthorized system use, especially across systems that process, store, or transmit Controlled Unclassified Information (CUI).
SI.L2-3.14.5[d] – Determine if malware protection mechanisms are enforced.
This objective ensures that your organization’s malware protection is not only deployed but enforced—meaning malware defenses cannot be disabled or bypassed without proper authorization, and protections are continuously active across systems processing Controlled Unclassified Information (CUI).
SI.L2-3.14.3[d] – Determine if flaws and vulnerabilities in organizational systems and applications are addressed.
This objective ensures your organization not only identifies flaws and vulnerabilities, but actively addresses and mitigates them to protect Controlled Unclassified Information (CUI). Detection without action is not sufficient.
SI.L2-3.14.7[a] – Identify unauthorized use of organizational systems.
This objective requires your organization to identify methods to detect and respond to unauthorized system usage, especially on systems that store, process, or transmit Controlled Unclassified Information (CUI).
SI.L2-3.14.7[c] – Determine if unauthorized use of organizational systems is identified.
This objective ensures your organization’s monitoring mechanisms are actively detecting unauthorized system usage, particularly across systems that process, store, or transmit Controlled Unclassified Information (CUI).