SI-4(2): Automated Tools For Real-Time Analysis
Control Family:
Parent Control:
CSF v1.1 References:
Threats Addressed:
Baselines:
- Moderate
- High
Next Version:
- NIST Special Publication 800-53 Revision 5:
- SI-4(2): Automated Tools and Mechanisms for Real-time Analysis
Control Statement
The organization employs automated tools to support near real-time analysis of events.
Supplemental Guidance
Automated tools include, for example, host-based, network-based, transport-based, or storage-based event monitoring tools or Security Information and Event Management (SIEM) technologies that provide real time analysis of alerts and/or notifications generated by organizational information systems.