Requirements / System and Information Integrity (SI)
SI.L2-3.14.6
Monitor Communications for Attacks
Official Source Material
Monitor organizational systems, including inbound and outbound communications traffic, to detect attacks and indicators of potential attacks.
Determine if:
- [a] the system is monitored to detect attacks and indicators of potential attacks;
- [b] inbound communications traffic is monitored to detect attacks and indicators of potential attacks; and
- [c] outbound communications traffic is monitored to detect attacks and indicators of potential attacks.
Source: CMMC Assessment Guide - Level 2, Version 2.13, September 2024
Practitioner Guidance
How to meet it
Blocking is not monitoring.
A firewall that drops traffic by rule is control. Monitoring is detection plus review. The intrusion prevention and gateway inspection features of the firewall you already own, turned on and alerting, create the detection. A person reviewing the alerts is what makes it monitoring.
Cover the system and both traffic directions.
Objective [a] is the systems themselves, covered by endpoint detection and log review. Objectives [b] and [c] are inbound and outbound traffic. Outbound is the half that catches real attacks: beaconing, the steady call home that malware makes, unauthorized data leaving, and connections to known-bad infrastructure. Enable inspection in both directions and alert on both.
Alerts need a named reader and a cadence.
Route detections to a mailbox or channel someone owns. Put the review on a schedule with a checklist: firewall alerts, endpoint detections, and the logs of the systems holding CUI, the Controlled Unclassified Information you protect. The review record is the evidence for all three objectives, and the records AU.L2-3.3.1 retains are what the review reads.
Scale the tooling to the environment, not to a security operations center ideal.
A small environment meets this with the firewall's security services alerting by email, endpoint detection and response, and a weekly review. A SIEM, the platform that collects and correlates alerts and logs in one place, earns its cost when alert volume outgrows a mailbox. Buying one does not satisfy the objectives. Reviewing what it raises does.
What falls short
- Detection features enabled with nobody assigned to read the alerts. Unreviewed alerts show detection exists and monitoring does not, which fails [a], [b], and [c] alike.