NIST 800-53 r5 · Controls catalogue · Family SI
SI-4System Monitoring
Monitor the system to detect: Attacks and indicators of potential attacks in accordance with the following monitoring objectives: {{ insert: param, si-04_odp.01 }} ; and Unauthorized local, network, and remote connections; Identify unauthorized use of the system through the following techniques and methods: {{ insert: param, si-04_odp.02 }}; Invoke internal monitoring capabilities or deploy monitoring devices: Strategically within the system to collect organization-determined essential information; and At ad hoc locations within the system to track specific types of transactions of interest to the organization; Analyze detected events and anomalies; Adjust the level of system monitoring activity when there is a change in risk to organizational operations and assets, individuals, other organizations, or the Nation; Obtain legal opinion regarding system monitoring activities; and Provide {{ insert: param, si-04_odp.03 }} to {{ insert: param, si-04_odp.04 }} {{ insert: param, si-04_odp.05 }}.
Last updated: 22 August 2026 07:11 UTC
Implementations targeting this control (3)
- aws-config-cloud-trail-log-file-validation-enabled CloudTrail log file validation is enabled AWS::CloudTrail::Trail partial detect enforce CIS §3.2Hub CloudTrail.4
- aws-config-guardduty-enabled-centralized Guardduty Enabled Centralized AWS::GuardDuty::Detector partial detect enforce
- aws-config-s3-event-notifications-enabled S3 Event Notifications Enabled AWS::S3::Bucket partial protect enforce
ATT&CK techniques this control mitigates (373)
- T1001 Data Obfuscation Command And Control
- T1001.001 Junk Data Command And Control
- T1001.002 Steganography Command And Control
- T1001.003 Protocol or Service Impersonation Command And Control
- T1003 OS Credential Dumping Credential Access
- T1003.001 LSASS Memory Credential Access
- T1003.002 Security Account Manager Credential Access
- T1003.003 NTDS Credential Access
- T1003.004 LSA Secrets Credential Access
- T1003.005 Cached Domain Credentials Credential Access
- T1003.006 DCSync Credential Access
- T1003.007 Proc Filesystem Credential Access
- T1003.008 /etc/passwd and /etc/shadow Credential Access
- T1005 Data from Local System Collection
- T1008 Fallback Channels Command And Control
- T1011 Exfiltration Over Other Network Medium Exfiltration
- T1011.001 Exfiltration Over Bluetooth Exfiltration
- T1020.001 Traffic Duplication Exfiltration
- T1021 Remote Services Lateral Movement
- T1021.001 Remote Desktop Protocol Lateral Movement
- T1021.002 SMB/Windows Admin Shares Lateral Movement
- T1021.003 Distributed Component Object Model Lateral Movement
- T1021.004 SSH Lateral Movement
- T1021.005 VNC Lateral Movement
- T1021.006 Windows Remote Management Lateral Movement
- T1021.008 Direct Cloud VM Connections Lateral Movement
- T1025 Data from Removable Media Collection
- T1027 Obfuscated Files or Information Stealth
- T1027.002 Software Packing Stealth
- T1027.007 Dynamic API Resolution Stealth
- T1027.008 Stripped Payloads Stealth
- T1027.009 Embedded Payloads Stealth
- T1027.010 Command Obfuscation Stealth
- T1027.011 Fileless Storage Stealth
- T1027.012 LNK Icon Smuggling Stealth
- T1029 Scheduled Transfer Exfiltration
- T1030 Data Transfer Size Limits Exfiltration
- T1036 Masquerading Stealth
- T1036.001 Invalid Code Signature Stealth
- T1036.003 Rename Legitimate Utilities Stealth
- T1036.005 Match Legitimate Resource Name or Location Stealth
- T1036.007 Double File Extension Stealth
- T1036.008 Masquerade File Type Stealth
- T1036.010 Masquerade Account Name Stealth
- T1037 Boot or Logon Initialization Scripts Persistence, Privilege Escalation
- T1037.002 Login Hook Persistence, Privilege Escalation
- T1037.003 Network Logon Script Persistence, Privilege Escalation
- T1037.004 RC Scripts Persistence, Privilege Escalation
- T1037.005 Startup Items Persistence, Privilege Escalation
- T1040 Network Sniffing Credential Access, Discovery
Weaknesses this control addresses (9)AI-assisted
CWEs ranked by how often they appear in real CVEs. The rationale describes how this control reduces exploitability of each weakness class.
| CWE | Name | CVEs | Why this control addresses it |
|---|---|---|---|
CWE-119 | Improper Restriction of Operations within the Bounds of a Memory Buffer | 14,500+ | Detects exploitation attempts that produce memory corruption, crashes, or anomalous behavior. |
CWE-352 | Cross-Site Request Forgery (CSRF) | 10,700+ | Detects anomalous request patterns consistent with cross-site request forgery. |
CWE-284 | Improper Access Control | 6,900+ | Directly detects unauthorized local/network/remote connections and system use that result from improper access control. |
CWE-74 | Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') | 5,200+ | Identifies indicators of injection attacks (command, SQL, LDAP, etc.) via anomaly and attack monitoring. |
CWE-287 | Improper Authentication | 5,200+ | Detects unauthorized use and connections stemming from authentication bypass or failure. |
CWE-400 | Uncontrolled Resource Consumption | 3,800+ | Monitors for resource exhaustion and denial-of-service patterns that indicate uncontrolled consumption. |
CWE-918 | Server-Side Request Forgery (SSRF) | 3,600+ | Detects server-side request forgery through monitoring of unexpected outbound connections. |
CWE-611 | Improper Restriction of XML External Entity Reference | 1,500+ | Identifies XML external entity processing via monitoring of unusual file/network access or resource usage. |
CWE-693 | Protection Mechanism Failure | 700+ | Reveals failures or bypasses of existing protection mechanisms via event and anomaly analysis. |
Top CVEs where this control is the strongest mitigation
| CVE | Risk | CVSS | EPSS | Match |
|---|---|---|---|---|
CVE-2024-25015 UPD | 6.0 | 7.5 | 0.0092 | good |
CVE-2023-28455 UPD | 5.9 | 7.5 | 0.0053 | good |
CVE-2023-28456 UPD | 5.9 | 7.5 | 0.0054 | good |
CVE-2023-49203 UPD | 5.9 | 7.5 | 0.0065 | good |
CVE-2026-68080 | 5.1 | 6.5 | 0.0042 | good |
CVE-2025-58066 UPD | 4.4 | 5.3 | 0.0034 | good |
CVE-2026-50045 | 4.3 | 5.3 | 0.0028 | good |
CVE-2024-25111 UPD | 8.6 | 8.6 | 0.6525 | partial |
CVE-2023-51803 UPD | 7.4 | 9.8 | 0.0070 | partial |
CVE-2026-43185 UPD | 7.4 | 9.8 | 0.0062 | partial |
CVE-2018-25159 UPD | 7.3 | 9.8 | 0.0039 | partial |
CVE-2025-3578 UPD | 7.0 | 9.3 | 0.0047 | partial |
CVE-2025-10728 UPD | 7.0 | 9.4 | 0.0020 | partial |
CVE-2026-40324 | 7.0 | 9.1 | 0.0090 | partial |
CVE-2026-32327 | 6.9 | 9.1 | 0.0048 | partial |
CVE-2024-37973 UPD | 6.6 | 8.8 | 0.0065 | partial |
CVE-2024-20311 UPD | 6.4 | 8.6 | 0.0080 | partial |
CVE-2024-4340 UPD | 6.4 | 7.5 | 0.0324 | partial |
CVE-2025-5302 UPD | 6.4 | 8.6 | 0.0028 | partial |
CVE-2024-5971 UPD | 6.3 | 7.5 | 0.0272 | partial |
CVE-2025-59789 | 6.2 | 7.5 | 0.0158 | partial |
CVE-2024-27454 UPD | 6.1 | 7.5 | 0.0120 | partial |
CVE-2024-34158 UPD | 6.1 | 7.5 | 0.0105 | partial |
CVE-2024-8176 UPD | 6.1 | 7.5 | 0.0130 | partial |
CVE-2024-32609 UPD | 6.0 | 7.5 | 0.0080 | partial |