Skip to content

Commit b038cb2

Browse files
authored
Update fedramp-other-controls.md
1 parent 5d6af3c commit b038cb2

File tree

1 file changed

+1
-1
lines changed

1 file changed

+1
-1
lines changed

articles/active-directory/standards/fedramp-other-controls.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -64,7 +64,7 @@ The guidance in the following table pertains to:
6464

6565
| FedRAMP Control ID and description | Azure AD guidance and recommendations |
6666
| - | - |
67-
| **SI-4 Information System Monitoring**<br>**The organization:**<br>**(a.)** Monitors the information system to detect:<br>**(1.)** Attacks and indicators of potential attacks in accordance with [*Assignment: organization-defined monitoring objectives*]; and<br>**(2.)** Unauthorized local, network, and remote connections;<br>**(b.)** Identifies unauthorized use of the information system through [*Assignment: organization-defined techniques and methods*];<br>**(c.)** Deploys monitoring devices (i) strategically within the information system to collect organization-determined essential information; and (ii) at ad hoc locations within the system to track specific types of transactions of interest to the organization;<br>**(d.)** Protects information obtained from intrusion-monitoring tools from unauthorized access, modification, and deletion;<br>**(e.)** Heightens the level of information system monitoring activity whenever there is an indication of increased risk to organizational operations and assets, individuals, other organizations, or the Nation based on law enforcement information, intelligence information, or other credible sources of information;<br>**(f.)** Obtains legal opinion with regard to information system monitoring activities in accordance with applicable federal laws, Executive Orders, directives, policies, or regulations; and<br>**(d.)** Provides [*Assignment: organization-defined information system monitoring information*] to [*Assignment: organization-defined personnel or roles] [Selection (one or more): as needed; [Assignment: organization-defined frequency]*].<br>**SI-4 Additional FedRAMP Requirements and Guidance:**<br>**Guidance:** See US-CERT Incident Response Reporting Guidelines.<br><br>**SI-04(1)**<br> The organization connects and configures individual intrusion detection tools into an information system-wide intrusion detection system. | Implement information system-wide monitoring, and the intrusion detection system. <p>Include all Azure AD logs (Audit, Sign-in, Identity Protection) within the information system monitoring solution. <p>Stream Azure AD logs into a SIEM solution (see IA-04). &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;|
67+
| **SI-4 Information System Monitoring**<br>**The organization:**<br>**(a.)** Monitors the information system to detect:<br>**(1.)** Attacks and indicators of potential attacks in accordance with [*Assignment: organization-defined monitoring objectives*]; and<br>**(2.)** Unauthorized local, network, and remote connections;<br>**(b.)** Identifies unauthorized use of the information system through [*Assignment: organization-defined techniques and methods*];<br>**(c.)** Deploys monitoring devices (i) strategically within the information system to collect organization-determined essential information; and (ii) at ad hoc locations within the system to track specific types of transactions of interest to the organization;<br>**(d.)** Protects information obtained from intrusion-monitoring tools from unauthorized access, modification, and deletion;<br>**(e.)** Heightens the level of information system monitoring activity whenever there is an indication of increased risk to organizational operations and assets, individuals, other organizations, or the Nation based on law enforcement information, intelligence information, or other credible sources of information;<br>**(f.)** Obtains legal opinion with regard to information system monitoring activities in accordance with applicable federal laws, Executive Orders, directives, policies, or regulations; and<br>**(d.)** Provides [*Assignment: organization-defined information system monitoring information*] to [*Assignment: organization-defined personnel or roles] [Selection (one or more): as needed; [Assignment: organization-defined frequency]*].<br>**SI-4 Additional FedRAMP Requirements and Guidance:**<br>**Guidance:** See US-CERT Incident Response Reporting Guidelines.<br><br>**SI-04(1)**<br> The organization connects and configures individual intrusion detection tools into an information system-wide intrusion detection system. | Implement information system-wide monitoring, and the intrusion detection system. <p>Include all Azure AD logs (Audit, Sign-in, Identity Protection) within the information system monitoring solution. <p>Stream Azure AD logs into a SIEM solution (see IA-04). &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;|
6868

6969
## Next steps
7070

0 commit comments

Comments
 (0)