PlumbTrackLive demoGRC Risk System

← internal audit

Audit — SI-4 — System Monitoring

Framework: NIST SP 800-53 Rev.5 SI-4 · Mark each check Pass / Fail / N/A; a Fail is a finding to remediate. · open the item

0 pass · 0 finding(s) · 0 N/A · 0 of 7 checked
Examine Examine the system monitoring architecture and confirm intrusion detection/prevention and network monitoring sensors are deployed at external boundaries and key internal segments to detect attacks and indicators of compromise (CIS Control 13 Network Monitoring and Defense).
Examine Examine the SIEM/log aggregation configuration and confirm required log sources are onboarded and correlation rules/alerts for suspicious activity are defined and enabled (CIS Control 8 Audit Log Management).
Examine Examine monitoring configuration to confirm both inbound and outbound communications traffic are monitored for unusual, unauthorized, or anomalous activity (e.g., data exfiltration, beaconing).
Test Generate a benign simulated indicator or test event and confirm an alert is produced and routed to the SOC/responders within the defined notification timeframe.
Interview How is monitoring coverage staffed and maintained (e.g., 24/7 coverage, analyst triage, escalation thresholds), and how are alerts prioritized?
Examine Examine a sample of generated alerts and confirm each was actioned via tickets and integrated with the incident response process rather than left unreviewed.
Examine Examine access controls and integrity protections on monitoring tools and collected monitoring data to confirm only authorized personnel can access or modify them.