SI-04.13 ยท Analyze Traffic and Event Patterns

Control Description

Analyze communications traffic and event patterns for the system; Develop profiles representing common traffic and event patterns; and Use the traffic and event profiles in tuning system-monitoring devices.

Impact Baselines
Security baselines where this control applies
Not in any baseline
Control Properties
SP800-53-enhancement
organization
Assurance
Enhancement
Control Statement
The control requirements

(a) Analyze communications traffic and event patterns for the system;

(b) Develop profiles representing common traffic and event patterns; and

(c) Use the traffic and event profiles in tuning system-monitoring devices.

Supplemental Guidance

Identifying and understanding common communications traffic and event patterns help organizations provide useful information to system monitoring devices to more effectively identify suspicious or anomalous traffic and events when they occur. Such information can help reduce the number of false positives and false negatives during system monitoring.