3.14 System & Information Integrity5 pts

3.14.6 — Monitor for attacks

Monitor organizational systems, including inbound and outbound communications traffic, to detect attacks and indicators of potential attacks.

You watch systems and traffic to detect attacks and indicators.

What it actually means

Active monitoring for attacks — inbound and outbound traffic and system activity — typically EDR plus network monitoring/IDS feeding your log review (3.3.5). 'Monitor outbound' matters: it's how you catch data exfiltration and beaconing.

Pass or fail — an assessor needs a "yes" to each

What to have ready

Where teams trip up

See where this control puts your score

Run all 110 requirements free in about 10 minutes — or draft your SSP language for this control. No signup.

Calculate your SPRS score →Draft your SSP language →

Connected requirements

More in System & Information Integrity (3.14)

← Back to the Control Library

The GovCon Compliance Brief
Get the next regulation change explained in plain English.

One CMMC / NIST 800-171 update, decoded, every other week. No spin, no sales pitch. Free.