{"data":{"id":"SI-05","name":"Security Alerts, Advisories, and Directives","family":"SI","family_name":"System and Information Integrity","withdrawn":false,"description":"a. Receive system security alerts, advisories, and directives from [Assignment: organization-defined external organizations] on an ongoing basis;\nb. Generate internal security alerts, advisories, and directives as deemed necessary;\nc. Disseminate security alerts, advisories, and directives to: [Selection (one or more): [Assignment: organization-defined personnel or roles]; [Assignment: organization-defined elements within the organization]; [Assignment: organization-defined external organizations]]; and\nd. Implement security directives in accordance with established time frames, or notify the issuing organization of the degree of noncompliance.","supplemental_guidance":"The Cybersecurity and Infrastructure Security Agency (CISA) generates security alerts and advisories to maintain situational awareness throughout the Federal Government. Security directives are issued by OMB or other designated organizations with the responsibility and authority to issue such directives. Compliance with security directives is essential due to the critical nature of many of these directives and the potential (immediate) adverse effects on organizational operations and assets, individuals, other organizations, and the Nation should the directives not be implemented in a timely manner. External organizations include supply chain partners, external mission or business partners, external service providers, and other peer or supporting organizations.","enhancements":[{"id":"SI-05(01)","name":"Automated Alerts and Advisories","statement":"Broadcast security alert and advisory information throughout the organization using [Assignment: organization-defined automated mechanisms].","baselines":["high"]}],"baseline_low":true,"baseline_moderate":true,"baseline_high":true,"nist_800_53":{"rev5":{"id":"SI-05","name":"Security Alerts, Advisories, and Directives","description":"a. Receive system security alerts, advisories, and directives from [Assignment: organization-defined external organizations] on an ongoing basis;\nb. Generate internal security alerts, advisories, and directives as deemed necessary;\nc. Disseminate security alerts, advisories, and directives to: [Selection (one or more): [Assignment: organization-defined personnel or roles]; [Assignment: organization-defined elements within the organization]; [Assignment: organization-defined external organizations]]; and\nd. Implement security directives in accordance with established time frames, or notify the issuing organization of the degree of noncompliance.","discussion":"The Cybersecurity and Infrastructure Security Agency (CISA) generates security alerts and advisories to maintain situational awareness throughout the Federal Government. Security directives are issued by OMB or other designated organizations with the responsibility and authority to issue such directives. Compliance with security directives is essential due to the critical nature of many of these directives and the potential (immediate) adverse effects on organizational operations and assets, individuals, other organizations, and the Nation should the directives not be implemented in a timely manner. External organizations include supply chain partners, external mission or business partners, external service providers, and other peer or supporting organizations.","related_controls":["PM-15","RA-05","SI-02"],"baseline_low":true,"baseline_moderate":true,"baseline_high":true,"baseline_privacy":false,"new_in_rev5":false,"changes_from_rev4":""}},"compliance_mappings":{"iso_27001_2022":["A.5.6","A.5.7","A.8.8"],"iso_27002_2022":["5.7","8.8"],"cobit_2019":[],"pci_dss_v4":["6.3"],"nist_csf_2":["DE.AE-07","ID.RA-01","ID.RA-02","ID.RA-03","ID.RA-08"],"cis_controls_v8":["CIS 7"],"soc2_tsc":["CC6.6","CC6.6-POF2","CC9.2-POF13"],"finos_ccc":["CCC-C10"],"iso_42001_2023":["A.3.3"],"iec_62443":[],"asd_e8":[],"nis2":[],"apra_cps_234":[],"mas_trm":[],"pra_op_resilience":[],"bsi_grundschutz":[],"anssi":["Hygiene.33","Hygiene.39","SecNumCloud.13.6"],"osfi_b13":["B-13.2.4","B-13.3.3"],"finma_circular":["IV.B.b(52)","IV.B.c(53)","IV.B.c(56)"],"gdpr":["Art.32(1)(d)"],"dora":["Art.10(1)","Art.13(1)"],"bio2":["5.7","8.8"],"rbi_csf":["Annex1.7","Annex1.13"],"fisc":["FISC.O2","FISC.O12"],"lgpd_bcb":["BCB.Art.6"],"hkma_tme1":["TME1.7.4"],"mlps_2":[],"dnb_good_practice":["DNB.3.1","DNB.15.1","DNB.19.2"],"cra":["CRA.Art14","CRA.II.4","CRA.II.5","CRA.II.8"],"swift_cscf":[],"cbb_tm":["TM-11","TM-13"],"nca_ecc":["2-10","2-13"],"qatar_nia":["IM","OS"],"sama_csf":["3.6"],"uae_ia":["T7"],"bom_ctrm":["4.1","5.1","5.3"],"cbe_csf":["CD-1","CTO-9"],"cbn_csf":["Part4"],"sa_js2":["JS2-7.6"],"bot_cyber":["Ch3.2","Ch4.1","Ch8.1"],"cpmi_pfmi":["CG.DE","CG.SA"],"eba_ict":["3.4.5","3.8(d)"],"ecb_croe":["CROE.2.4","CROE.2.5.1","CROE.2.5.3","CROE.2.7.1","CROE.2.7.2","CROE.2.8.2"],"ffiec_is":["II.A.1","III.A","III.B","III.C","III.D"],"hipaa_sr":["§164.308(a)(5)(ii)(A)","§164.308(a)(6)(ii)"],"iosco_cyber":["DET-3","ID-3","SA-1","SA-3"],"nydfs_500":["500.5","500.10"],"sebi_cscrf":["DE.DP","RS.CO"],"cmmc_2":["IR","SI"],"nerc_cip":[],"nrc_73_54":[],"tsa_psd":[],"ieee_1686":[],"ferc_cip":[],"doe_c2m2":["THREAT"],"api_1164":[],"awia":[],"iaea_nss":[],"pci_pts":[],"fips_140":[],"cbest":["CBEST.2"],"tiber_eu":["TIBER.GTL","TIBER.TTI"],"pci_hsm":[],"common_criteria":[],"isae_3402":[],"fca_sysc_13":["SYSC 13.4"],"fda_21_cfr_11":[],"fda_cyber":["524B-2","524B-3","CVD-1","CVD-2","INC-3","MON-1","MON-2","MON-3","SBOM-3"],"hitrust_csf":["09.c","10.e","11.a"],"iso_27799":["12.5","16.2"],"lloyds_ms":["CRM.2","MS8.5","MS8.11"],"naic_ds":["4-monitoring"],"nhs_dspt":["NDG-6.3","NDG-8.2"],"pra_ss1_23":["P5.3"],"solvency_ii":["EIOPA-ICT-4.9"],"owasp_masvs_v2":[],"csa_ccm_v4":["TVM-07"],"csa_aicm":["TVM-07"],"ccss_v9":[],"mica":["Art.35(1)","Art.62(8)"],"basel_sco60":[],"bssc":["NOS-06"],"sec_custody_digital":[],"dpdpa":[]},"attack_techniques":[{"id":"T1068","name":"Exploitation for Privilege Escalation","tactics":["privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Timely receipt and distribution of security advisories about privilege escalation vulnerabilities enables rapid patching before adversaries can develop and deploy exploitation techniques."},{"id":"T1210","name":"Exploitation of Remote Services","tactics":["lateral-movement"],"mapping_type":"mitigates","mapping_rationale":"Monitoring security alerts for vulnerabilities in network-exposed services enables proactive patching that eliminates the remote service exploitation vectors adversaries target for lateral movement."},{"id":"T1211","name":"Exploitation for Defense Evasion","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Security advisories about defense evasion vulnerabilities in security tools and controls enable organizations to patch before adversaries exploit these weaknesses to bypass protective mechanisms."},{"id":"T1212","name":"Exploitation for Credential Access","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"Timely awareness of authentication and credential access vulnerabilities through security advisories enables rapid remediation before adversaries exploit these weaknesses to harvest credentials."}],"metadata":{"last_reviewed":"2026-10-03","review_notes":"2026-10-03: iso_27001_2022 A.5.6 added from NIST's SP 800-53 Rev 5 to ISO/IEC 27001:2022 crosswalk (OLIR entry 155), which OSA's mapping now takes as its base. 2026-10-03: nist_csf_2 ID.RA-03 added from NIST's CSF 2.0 to SP 800-53 Rev 5.2.0 crosswalk (OLIR entry 186), which OSA's mapping now takes as its base.","mapping_status":"complete"},"function":"detective","used_by_patterns":["SP-001","SP-002","SP-016","SP-023","SP-026","SP-031","SP-046","SP-048"]}}