03.14: System and Information Integrity
Controls
03.14.01: Flaw Remediation
Identify, report, and correct system flaws. Install security-relevant software and firmware updates within [Assignment: organization-defined time period] of the release of the updates.
03.14.02: Malicious Code Protection
Implement malicious code protection mechanisms at system entry and exit points to detect and eradicate malicious code. Update malicious code protection mechanisms as new releases are available in accordance with configuration management policies and procedures. Configure malicious code protection mechanisms to: Perform scans of the system [Assignment: organization-defined frequency] and real-time scans of files from…
03.14.03: Security Alerts, Advisories, and Directives
Receive system security alerts, advisories, and directives from external organizations on an ongoing basis. Generate and disseminate internal system security alerts, advisories, and directives, as necessary.
03.14.06: System Monitoring
Monitor the system to detect: Attacks and indicators of potential attacks and Unauthorized connections. Identify unauthorized use of the system. Monitor inbound and outbound communications traffic to detect unusual or unauthorized activities or conditions.
03.14.08: Information Management and Retention
Manage and retain CUI within the system and CUI output from the system in accordance with applicable laws, Executive Orders, directives, regulations, policies, standards, guidelines, and operational requirements.