Cyber Resilience

NIST 800-53 r5 · Controls catalogue · Family SI

SI-4System Monitoring

Monitor the system to detect: Attacks and indicators of potential attacks in accordance with the following monitoring objectives: {{ insert: param, si-04_odp.01 }} ; and Unauthorized local, network, and remote connections; Identify unauthorized use of the system through the following techniques and methods: {{ insert: param, si-04_odp.02 }}; Invoke internal monitoring capabilities or deploy monitoring devices: Strategically within the system to collect organization-determined essential information; and At ad hoc locations within the system to track specific types of transactions of interest to the organization; Analyze detected events and anomalies; Adjust the level of system monitoring activity when there is a change in risk to organizational operations and assets, individuals, other organizations, or the Nation; Obtain legal opinion regarding system monitoring activities; and Provide {{ insert: param, si-04_odp.03 }} to {{ insert: param, si-04_odp.04 }} {{ insert: param, si-04_odp.05 }}.

Last updated: 22 August 2026 07:11 UTC

Implementations targeting this control (3)

ATT&CK techniques this control mitigates (373)

Weaknesses this control addresses (9)AI-assisted

CWEs ranked by how often they appear in real CVEs. The rationale describes how this control reduces exploitability of each weakness class.

CWE Name CVEs Why this control addresses it
CWE-119Improper Restriction of Operations within the Bounds of a Memory Buffer14,500+Detects exploitation attempts that produce memory corruption, crashes, or anomalous behavior.
CWE-352Cross-Site Request Forgery (CSRF)10,700+Detects anomalous request patterns consistent with cross-site request forgery.
CWE-284Improper Access Control6,900+Directly detects unauthorized local/network/remote connections and system use that result from improper access control.
CWE-74Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')5,200+Identifies indicators of injection attacks (command, SQL, LDAP, etc.) via anomaly and attack monitoring.
CWE-287Improper Authentication5,200+Detects unauthorized use and connections stemming from authentication bypass or failure.
CWE-400Uncontrolled Resource Consumption3,800+Monitors for resource exhaustion and denial-of-service patterns that indicate uncontrolled consumption.
CWE-918Server-Side Request Forgery (SSRF)3,600+Detects server-side request forgery through monitoring of unexpected outbound connections.
CWE-611Improper Restriction of XML External Entity Reference1,500+Identifies XML external entity processing via monitoring of unusual file/network access or resource usage.
CWE-693Protection Mechanism Failure700+Reveals failures or bypasses of existing protection mechanisms via event and anomaly analysis.

Top CVEs where this control is the strongest mitigation

CVE Risk CVSS EPSS Match
CVE-2024-25015 6.07.50.0092good
CVE-2023-28455 5.97.50.0053good
CVE-2023-28456 5.97.50.0054good
CVE-2023-49203 5.97.50.0065good
CVE-2026-680805.16.50.0042good
CVE-2025-58066 4.45.30.0034good
CVE-2026-500454.35.30.0028good
CVE-2024-25111 8.68.60.6525partial
CVE-2023-51803 7.49.80.0070partial
CVE-2026-43185 7.49.80.0062partial
CVE-2018-25159 7.39.80.0039partial
CVE-2025-3578 7.09.30.0047partial
CVE-2025-10728 7.09.40.0020partial
CVE-2026-403247.09.10.0090partial
CVE-2026-323276.99.10.0048partial
CVE-2024-37973 6.68.80.0065partial
CVE-2024-20311 6.48.60.0080partial
CVE-2024-4340 6.47.50.0324partial
CVE-2025-5302 6.48.60.0028partial
CVE-2024-5971 6.37.50.0272partial
CVE-2025-597896.27.50.0158partial
CVE-2024-27454 6.17.50.0120partial
CVE-2024-34158 6.17.50.0105partial
CVE-2024-8176 6.17.50.0130partial
CVE-2024-32609 6.07.50.0080partial

Other controls in family SI

SI-1 SI-10 SI-11 SI-12 SI-13 SI-14 SI-15 SI-16 SI-17 SI-18 SI-19 SI-2 SI-20 SI-21 SI-22 SI-23 SI-3 SI-5 SI-6 SI-7 SI-8 SI-9