System integrity verification and integrity checking Log analysis White Listing Black Listing Data Loss Prevention (DLP) 10.2. Used to detect changes to critical system components such as files, directories or services. These changes may alert a system administrator to unauthorized changes that could signify an attack on the system and inadvertent system changes that render the system open to attack. Involves collecting and analyzing event logs using pattern recognition to detect anomalous activities Lists the authorized activities and applications and permits their usage Lists the non‐authorized activities and applications and prevents their usage Data Egress monitoring and control Reporting Information Security Incidents Objective: Mandatory Control 1: Mandatory Control 2: Mandatory Control 3: Mandatory Control 4: Recommended Control 1: Recommended Control 2: Reporting information security incidents, assists in maintaining an accurate threat environment picture for government systems Agencies must direct personnel to report information security incidents to an ITSM as soon as possible after the information security incident is discovered in accordance with agency procedures The ITSM must keep the CISO fully informed of information security incidents within an agency The Agency ITSM must report significant information security incidents to the BCC Agencies that outsource their information technology services and functions must ensure that the service provider consults with the agency when an information security incident occurs Agencies should: encourage personnel to note and report any observed or suspected security weaknesses in, or threats to, systems or services establish and follow procedures for reporting software malfunctions put mechanisms in place to enable the types, volumes and costs of information security incidents and malfunctions to be quantified and monitored deal with the violation of agency information security policies and procedures by personnel through a formal disciplinary process Agencies should formally report information security incidents 43

Select target paragraph3