SI-05 Security Alerts, Advisories, and Directives
a. Receive system security alerts, advisories, and directives from si-05_odp.01 on an ongoing basis;
b. Generate internal security alerts, advisories, and directives as deemed necessary;
c. Disseminate security alerts, advisories, and directives to: si-05_odp.02 ; and
d. Implement security directives in accordance with established time frames, or notify the issuing organization of the degree of noncompliance.
Parameter ID | Definition |
---|---|
si-05_odp.01 | external organizations |
si-05_odp.02 |
Selection (one-or-more):
|
si-05_odp.03 | personnel or roles |
si-05_odp.04 | elements |
si-05_odp.05 | external organizations |
Baselines
- L
- M
- H
- P
Guidance
The Cybersecurity and Infrastructure Security Agency (CISA) generates security alerts and advisories to maintain situational awareness throughout the Federal Government. Security directives are issued by OMB or other designated organizations with the responsibility and authority to issue such directives. Compliance with security directives is essential due to the critical nature of many of these directives and the potential (immediate) adverse effects on organizational operations and assets, individuals, other organizations, and the Nation should the directives not be implemented in a timely manner. External organizations include supply chain partners, external mission or business partners, external service providers, and other peer or supporting organizations.
References 1
- SP 800-40 Souppaya MP, Scarfone KA (2013) Guide to Enterprise Patch Management Technologies. (National Institute of Standards and Technology, Gaithersburg, MD), NIST Special Publication (SP) 800-40, Rev. 3.
Control Enhancements 1
Related controls 3
- PM-15 Security and Privacy Groups and Associations L M H P
- RA-05 Vulnerability Monitoring and Scanning L M H P
- SI-02 Flaw Remediation L M H P