03.14: System and Information Integrity

Controls

03.14.01: Flaw Remediation

Identify, report, and correct system flaws. Install security-relevant software and firmware updates within [Assignment: organization-defined time period] of the release of the updates.

03.14.02: Malicious Code Protection

Implement malicious code protection mechanisms at system entry and exit points to detect and eradicate malicious code. Update malicious code protection mechanisms as new releases are available in accordance with configuration management policies and procedures. Configure malicious code protection mechanisms to: Perform scans of the system [Assignment: organization-defined frequency] and real-time scans of files from…

03.14.06: System Monitoring

Monitor the system to detect: Attacks and indicators of potential attacks and Unauthorized connections. Identify unauthorized use of the system. Monitor inbound and outbound communications traffic to detect unusual or unauthorized activities or conditions.

03.14.08: Information Management and Retention

Manage and retain CUI within the system and CUI output from the system in accordance with applicable laws, Executive Orders, directives, regulations, policies, standards, guidelines, and operational requirements.