# SI-05 Security Alerts, Advisories, and Directives

NIST SP 800-53 control. Family: SI System and Information Integrity. Function: detective. Baselines: low, moderate, high. Mapping licence: CC BY-SA 4.0.

Statement: a. Receive system security alerts, advisories, and directives from [Assignment: organization-defined external organizations] on an ongoing basis; b. Generate internal security alerts, advisories, and directives as deemed necessary; c. Disseminate security alerts, advisories, and directives to: [Selection (one or more): [Assignment: organization-defined personnel or roles]; [Assignment: organization-defined elements within the organization]; [Assignment: organization-defined external organizations]]; and d. Implement security directives in accordance with established time frames, or notify the issuing organization of the degree of noncompliance.
Guidance: The Cybersecurity and Infrastructure Security Agency (CISA) generates security alerts and advisories to maintain situational awareness throughout the Federal Government. Security directives are issued by OMB or other designated organizations with the responsibility and authority to issue such directives. Compliance with security directives is essential due to the critical nature of many of these directives and the potential (immediate) adverse effects on organizational operations and assets, individuals, other organizations, and the Nation should the directives not be implemented in a timely manner. External organizations include supply chain partners, external mission or business partners, external service providers, and other peer or supporting organizations.

## Enhancements (1)
- SI-05(01) Automated Alerts and Advisories. Baselines: high
Each enhancement's statement: /api/v1/controls/SI-05?fields=enhancements

## Patterns that use it (8)
- Important (4): SP-016 DMZ Module; SP-031 Security Monitoring and Response; SP-046 External Attack Surface Management; SP-048 Offensive AI and Deepfake Defence (draft)
- Standard (4): SP-001 Client Module; SP-002 Server Module; SP-023 Industrial Control Systems; SP-026 PCI Full Environment

## Clauses by framework (55 frameworks)
- iso_27001_2022: A.5.6, A.5.7, A.8.8. OSA's own, not in NIST's crosswalk: A.5.7
- iso_27002_2022: 5.7, 8.8
- pci_dss_v4: 6.3
- nist_csf_2: DE.AE-07, ID.RA-01, ID.RA-02, ID.RA-03, ID.RA-08. OSA's own, not in NIST's crosswalk: DE.AE-07, ID.RA-08
- cis_controls_v8: CIS 7
- soc2_tsc: CC6.6, CC6.6-POF2, CC9.2-POF13
- finos_ccc: CCC-C10
- iso_42001_2023: A.3.3
- anssi: Hygiene.33, Hygiene.39, SecNumCloud.13.6
- osfi_b13: B-13.2.4, B-13.3.3
- finma_circular: IV.B.b(52), IV.B.c(53), IV.B.c(56)
- gdpr: Art.32(1)(d)
- dora: Art.10(1), Art.13(1)
- bio2: 5.7, 8.8
- rbi_csf: Annex1.7, Annex1.13
- fisc: FISC.O2, FISC.O12
- lgpd_bcb: BCB.Art.6
- hkma_tme1: TME1.7.4
- dnb_good_practice: DNB.3.1, DNB.15.1, DNB.19.2
- cra: CRA.Art14, CRA.II.4, CRA.II.5, CRA.II.8
- cbb_tm: TM-11, TM-13
- nca_ecc: 2-10, 2-13
- qatar_nia: IM, OS
- sama_csf: 3.6
- uae_ia: T7
- bom_ctrm: 4.1, 5.1, 5.3
- cbe_csf: CD-1, CTO-9
- cbn_csf: Part4
- sa_js2: JS2-7.6
- bot_cyber: Ch3.2, Ch4.1, Ch8.1
- cpmi_pfmi: CG.DE, CG.SA
- eba_ict: 3.4.5, 3.8(d)
- ecb_croe: CROE.2.4, CROE.2.5.1, CROE.2.5.3, CROE.2.7.1, CROE.2.7.2, CROE.2.8.2
- ffiec_is: II.A.1, III.A, III.B, III.C, III.D
- hipaa_sr: §164.308(a)(5)(ii)(A), §164.308(a)(6)(ii)
- iosco_cyber: DET-3, ID-3, SA-1, SA-3
- nydfs_500: 500.5, 500.10
- sebi_cscrf: DE.DP, RS.CO
- cmmc_2: IR, SI
- doe_c2m2: THREAT
- cbest: CBEST.2
- tiber_eu: TIBER.GTL, TIBER.TTI
- fca_sysc_13: SYSC 13.4
- fda_cyber: 524B-2, 524B-3, CVD-1, CVD-2, INC-3, MON-1, MON-2, MON-3, SBOM-3
- hitrust_csf: 09.c, 10.e, 11.a
- iso_27799: 12.5, 16.2
- lloyds_ms: CRM.2, MS8.5, MS8.11
- naic_ds: 4-monitoring
- nhs_dspt: NDG-6.3, NDG-8.2
- pra_ss1_23: P5.3
- solvency_ii: EIOPA-ICT-4.9
- csa_ccm_v4: TVM-07
- csa_aicm: TVM-07
- mica: Art.35(1), Art.62(8)
- bssc: NOS-06
OSA's mapping for iso_27001_2022 and nist_csf_2 takes NIST's published crosswalk as its base. A clause not marked as OSA's own is in that crosswalk.

## More
- This control as JSON, with guidance and ATT&CK techniques: /api/v1/controls/SI-05
- Clauses only: /api/v1/controls/SI-05?fields=mappings
- Page for people: /controls/si-05/
