|
controlAU-13

Monitoring for Information Disclosure (AU-13)

Monitor [organization-defined] [organization-defined] for evidence of unauthorized disclosure of organizational information; and If an information disclosure is discovered:

auditaccountabilitylogging

Why These Connect

Maps To5

These are equivalent or closely aligned requirements in other frameworks.

Supports13

These related controls work together — a change to one may affect the others.

Enhances3

These enhancements add specific capabilities or refinements to the base control.

Cross-Framework Mappings(5)

PR.DS-10PR.DS-10Final
NIST OLIR informative reference — Cybersecurity Framework v2.0 to SP 800-53 Rev 5
DE.CM-03DE.CM-03Final
NIST OLIR informative reference — Cybersecurity Framework v2.0 to SP 800-53 Rev 5
ISO 27001ISO/IEC 27001:20222 mappingsFinal
NIST OLIR informative reference — SP 800-53 Rev 5 to ISO/IEC 27001:2022
PR.DS-10PR.DS-10Final
NIST OLIR informative reference — Cybersecurity Framework v2.0 to SP 800-53 Rev 5
DE.CM-03DE.CM-03Final
NIST OLIR informative reference — Cybersecurity Framework v2.0 to SP 800-53 Rev 5

Organization-Defined Parameters(4)

Assignmentorganization-defined open-source information and/or information sites
Assignmentorganization-defined frequency
Assignmentorganization-defined personnel or roles
Assignmentorganization-defined additional actions

Control Enhancements(3)