AU-13 Monitoring for Information Disclosure. Monitor [organization-defined] [organization-defined] for evidence of unauthorized disclosure of organizational information; and If an information disclosure is discovered: Notify [organization-defined] ; and Take the following additional actions: [organization-defined]
Monitoring for Information Disclosure. Monitor [organization-defined] [organization-defined] for evidence of unauthorized disclosure of organizational information; and If an information disclosure is discovered: Notify [.
5
artefacts
2
held by a system
2
at each review
moderate
to go live
SIEM / log platform
where the evidence lives
teal = a system already holds it · olive = produced at each review
system holds itEvidence a system already holds
- The defined open source information sites, forums and paste sites monitored, and the monitoring frequency · SIEM / log platform
- Notification records showing the defined personnel were alerted when a disclosure was found · Policy repository / GRC workspace
periodic reviewEvidence produced at each review
- Monitoring output records covering the review period, including nil findings · SIEM / log platform
- The additional response actions defined and evidence they were executed on a real finding · Policy repository / GRC workspace
governing documentDocuments that govern the control
- Search terms or organisational identifiers monitored for, such as domains, code signatures or document markings · Policy repository / GRC workspace
First move
Start with the 2 of 5 artefacts that already live in a system (SIEM / log platform); keep the periodic reviews but log each one as a dated record with a named reviewer.
Common gaps auditors find
- Monitoring covers brand mentions but not the credential dumps and code repositories where disclosure actually surfaces
- Findings routed to marketing or legal without ever reaching incident response
- Frequency undefined, so monitoring happens when someone remembers
Do this for your whole sheet
Paste the rows you run your controls from and get this mapping for every control at once, with the periodic-review ones flagged and a first move per row. No account for the first run.
Build my evidence sheetAU-12 Audit record generation · AU-14 Session Audit. Provide and implement the capability for [organization-defined] to [organization-defined] the content of a user session under [organization-defined] ; and Develop, integrate, and use session auditing activities in consultation with legal counsel and