SI-04.25 ยท Optimize Network Traffic Analysis

Control Description

Provide visibility into network traffic at external and key internal system interfaces to optimize the effectiveness of monitoring devices.

Impact Baselines
Security baselines where this control applies
Not in any baseline
Control Properties
SP800-53-enhancement
system
Assurance
Enhancement
Control Statement
The control requirements

Provide visibility into network traffic at external and key internal system interfaces to optimize the effectiveness of monitoring devices.

Supplemental Guidance

Encrypted traffic, asymmetric routing architectures, capacity and latency limitations, and transitioning from older to newer technologies (e.g., IPv4 to IPv6 network protocol transition) may result in blind spots for organizations when analyzing network traffic. Collecting, decrypting, pre-processing, and distributing only relevant traffic to monitoring devices can streamline the efficiency and use of devices and optimize traffic analysis.