|
controlAU-13
Monitoring for Information Disclosure (AU-13)
Monitor [organization-defined] [organization-defined] for evidence of unauthorized disclosure of organizational information; and If an information disclosure is discovered:
auditaccountabilitylogging
Why These Connect
Maps To5
These are equivalent or closely aligned requirements in other frameworks.
Supports13
These related controls work together — a change to one may affect the others.
Enhances3
These enhancements add specific capabilities or refinements to the base control.
Related Controls(9)
AC-22Publicly Accessible Content (AC-22)
LMH
PE-3Physical Access Control (PE-3)LMH
PM-12Insider Threat Program (PM-12)RA-5Vulnerability Monitoring and Scanning (RA-5)LMH
SC-7Boundary Protection (SC-7)LMH
SI-20Tainting (SI-20)CA-7Continuous Monitoring (CA-7)LMH
PM-31Continuous Monitoring Strategy (PM-31)SI-4System Monitoring (SI-4)LMH
Cross-Framework Mappings(5)
PR.DS-10PR.DS-10Final
NIST OLIR informative reference — Cybersecurity Framework v2.0 to SP 800-53 Rev 5
DE.CM-03DE.CM-03Final
NIST OLIR informative reference — Cybersecurity Framework v2.0 to SP 800-53 Rev 5
ISO 27001ISO/IEC 27001:20222 mappingsFinal
NIST OLIR informative reference — SP 800-53 Rev 5 to ISO/IEC 27001:2022
PR.DS-10PR.DS-10Final
NIST OLIR informative reference — Cybersecurity Framework v2.0 to SP 800-53 Rev 5
DE.CM-03DE.CM-03Final
NIST OLIR informative reference — Cybersecurity Framework v2.0 to SP 800-53 Rev 5
Organization-Defined Parameters(4)
Assignmentorganization-defined open-source information and/or information sites
Assignmentorganization-defined frequency
Assignmentorganization-defined personnel or roles
Assignmentorganization-defined additional actions