Requirements / System and Information Integrity (SI)
SI.L2-3.14.3
Security Alerts & Advisories
Official Source Material
Monitor system security alerts and advisories and take action in response.
Determine if:
- [a] response actions to system security alerts and advisories are identified;
- [b] system security alerts and advisories are monitored; and
- [c] actions in response to system security alerts and advisories are taken.
Source: CMMC Assessment Guide - Level 2, Version 2.13, September 2024
Practitioner Guidance
How to meet it
Subscribe to the sources that match your stack, and name them.
Alerts from CISA, the federal cybersecurity agency, plus the security bulletins for the products you actually run are the working set. Objective [b] is met by receiving and reviewing them on a cadence tied to how often they arrive. The named source list in your procedure is the first thing an assessor asks for.
Decide response actions before the advisory arrives.
Objective [a] wants the playbook in advance: assess applicability, check exposure, patch or reconfigure under your SI.L2-3.14.1 timeframes, and notify the people affected. Three sentences in the procedure cover it.
Keep receipts that action followed.
Objective [c] is the record: the advisory reviewed, the applicability call, and the ticket or change that followed when it applied. An advisory judged not applicable is also a record. A one-line log entry shows the process ran.
What falls short
- Subscriptions with no review. Alert emails accumulating unread in a mailbox show monitoring under [b] is not happening, and nothing can follow for [c].