AU-13 ยท Monitoring for Information Disclosure

Control Description

Monitor {{ insert: param, au-13_odp.01 }} {{ insert: param, au-13_odp.02 }} for evidence of unauthorized disclosure of organizational information; and If an information disclosure is discovered:

Impact Baselines
Security baselines where this control applies
Not in any baseline
Control Properties
SP800-53
organization
Assurance
Control Statement
The control requirements

a. Monitor {{ insert: param, au-13_odp.01 }} {{ insert: param, au-13_odp.02 }} for evidence of unauthorized disclosure of organizational information; and

b. If an information disclosure is discovered:

1. Notify {{ insert: param, au-13_odp.03 }} ; and

2. Take the following additional actions: {{ insert: param, au-13_odp.04 }}.

Supplemental Guidance

Unauthorized disclosure of information is a form of data leakage. Open-source information includes social networking sites and code-sharing platforms and repositories. Examples of organizational information include personally identifiable information retained by the organization or proprietary information generated by the organization.

Related NIST Controls
Other NIST 800-53 controls related to this one