Browse 1,193 controls and enhancements across 20 security and privacy families. Use the GovRAMP crosswalk to locate controls referenced by Security Snapshot, Core, and Moderate.
A shared catalog supports common-control planning; designation as a common, hybrid, or system-specific control depends on your organization’s implementation and inheritance decisions.
Sources and crosswalk scope
NIST OSCAL content 5.1.1+u4, retrieved 2026-09-18. GovRAMP Snapshot v1.4 and Core selection from Moderate v1.06 reference the December 2020 Rev. 5 text. Mappings establish exact identifier correspondence, not identical requirements, inherited implementation, or GovRAMP authorization. GovRAMP parameters and additional requirements remain authoritative for each program. Full Moderate, High, and other programs are not mapped here. Withdrawn controls are retained for reference.
Official pinned NIST sourceSHA-256: 81cf2de45ede9aef3de7ce09d65ea9d32f662c483bbf916f6e346292b22f7763
System and Information Integrity · Enhancement
SI-4(5) · System-generated Alerts
View parent controlControl statement and discussion
NIST control statement
Alert [Assignment: personnel or roles] when the following system-generated indications of compromise or potential compromise occur: [Assignment: compromise indicators].
Discussion
Alerts may be generated from a variety of sources, including audit records or inputs from malicious code protection mechanisms, intrusion detection or prevention mechanisms, or boundary protection devices such as firewalls, gateways, and routers. Alerts can be automated and may be transmitted telephonically, by electronic mail messages, or by text messaging. Organizational personnel on the alert notification list can include system administrators, mission or business owners, system owners, information owners/stewards, senior agency information security officers, senior agency officials for privacy, system security officers, or privacy officers. In contrast to alerts generated by the system, alerts generated by organizations in [SI-4(12)](#si-4.12) focus on information sources external to the system, such as suspicious activity reports and reports on potential insider threats.
GovRAMP crosswalk
- GovRAMP Moderate Readiness · SI-4 (5) — Direct NIST identifier reference. GovRAMP source matrix
System and Information Integrity · Enhancement
SI-4(7) · Automated Response to Suspicious Events
View parent controlControl statement and discussion
NIST control statement
(a) Notify [Assignment: incident response personnel] of detected suspicious events; and
(b) Take the following actions upon detection: [Assignment: least-disruptive actions].
Discussion
Least-disruptive actions include initiating requests for human responses.
GovRAMP crosswalk
Not selected in the imported Snapshot or Core sets. This does not establish exclusion from other GovRAMP baselines.
System and Information Integrity · Enhancement
SI-4(9) · Testing of Monitoring Tools and Mechanisms
View parent controlControl statement and discussion
NIST control statement
Test intrusion-monitoring tools and mechanisms [Assignment: frequency].
Discussion
Testing intrusion-monitoring tools and mechanisms is necessary to ensure that the tools and mechanisms are operating correctly and continue to satisfy the monitoring objectives of organizations. The frequency and depth of testing depends on the types of tools and mechanisms used by organizations and the methods of deployment.
GovRAMP crosswalk
Not selected in the imported Snapshot or Core sets. This does not establish exclusion from other GovRAMP baselines.
System and Information Integrity · Enhancement
SI-4(10) · Visibility of Encrypted Communications
View parent controlControl statement and discussion
NIST control statement
Make provisions so that [Assignment: encrypted communications traffic] is visible to [Assignment: system monitoring tools and mechanisms].
Discussion
Organizations balance the need to encrypt communications traffic to protect data confidentiality with the need to maintain visibility into such traffic from a monitoring perspective. Organizations determine whether the visibility requirement applies to internal encrypted traffic, encrypted traffic intended for external destinations, or a subset of the traffic types.
GovRAMP crosswalk
Not selected in the imported Snapshot or Core sets. This does not establish exclusion from other GovRAMP baselines.
System and Information Integrity · Enhancement
SI-4(11) · Analyze Communications Traffic Anomalies
View parent controlControl statement and discussion
NIST control statement
Analyze outbound communications traffic at the external interfaces to the system and selected [Assignment: interior points] to discover anomalies.
Discussion
Organization-defined interior points include subnetworks and subsystems. Anomalies within organizational systems include large file transfers, long-time persistent connections, attempts to access information from unexpected locations, the use of unusual protocols and ports, the use of unmonitored network protocols (e.g., IPv6 usage during IPv4 transition), and attempted communications with suspected malicious external addresses.
GovRAMP crosswalk
Not selected in the imported Snapshot or Core sets. This does not establish exclusion from other GovRAMP baselines.
System and Information Integrity · Enhancement
SI-4(12) · Automated Organization-generated Alerts
View parent controlControl statement and discussion
NIST control statement
Alert [Assignment: personnel or roles] using [Assignment: automated mechanisms] when the following indications of inappropriate or unusual activities with security or privacy implications occur: [Assignment: activities that trigger alerts].
Discussion
Organizational personnel on the system alert notification list include system administrators, mission or business owners, system owners, senior agency information security officer, senior agency official for privacy, system security officers, or privacy officers. Automated organization-generated alerts are the security alerts generated by organizations and transmitted using automated means. The sources for organization-generated alerts are focused on other entities such as suspicious activity reports and reports on potential insider threats. In contrast to alerts generated by the organization, alerts generated by the system in [SI-4(5)](#si-4.5) focus on information sources that are internal to the systems, such as audit records.
GovRAMP crosswalk
Not selected in the imported Snapshot or Core sets. This does not establish exclusion from other GovRAMP baselines.
System and Information Integrity · Enhancement
SI-4(13) · Analyze Traffic and Event Patterns
View parent controlControl statement and discussion
NIST control statement
(a) Analyze communications traffic and event patterns for the system;
(b) Develop profiles representing common traffic and event patterns; and
(c) Use the traffic and event profiles in tuning system-monitoring devices.
Discussion
Identifying and understanding common communications traffic and event patterns help organizations provide useful information to system monitoring devices to more effectively identify suspicious or anomalous traffic and events when they occur. Such information can help reduce the number of false positives and false negatives during system monitoring.
GovRAMP crosswalk
Not selected in the imported Snapshot or Core sets. This does not establish exclusion from other GovRAMP baselines.
System and Information Integrity · Enhancement
SI-4(14) · Wireless Intrusion Detection
View parent controlControl statement and discussion
NIST control statement
Employ a wireless intrusion detection system to identify rogue wireless devices and to detect attack attempts and potential compromises or breaches to the system.
Discussion
Wireless signals may radiate beyond organizational facilities. Organizations proactively search for unauthorized wireless connections, including the conduct of thorough scans for unauthorized wireless access points. Wireless scans are not limited to those areas within facilities containing systems but also include areas outside of facilities to verify that unauthorized wireless access points are not connected to organizational systems.
GovRAMP crosswalk
Not selected in the imported Snapshot or Core sets. This does not establish exclusion from other GovRAMP baselines.
System and Information Integrity · Enhancement
SI-4(15) · Wireless to Wireline Communications
View parent controlControl statement and discussion
NIST control statement
Employ an intrusion detection system to monitor wireless communications traffic as the traffic passes from wireless to wireline networks.
Discussion
Wireless networks are inherently less secure than wired networks. For example, wireless networks are more susceptible to eavesdroppers or traffic analysis than wireline networks. When wireless to wireline communications exist, the wireless network could become a port of entry into the wired network. Given the greater facility of unauthorized network access via wireless access points compared to unauthorized wired network access from within the physical boundaries of the system, additional monitoring of transitioning traffic between wireless and wired networks may be necessary to detect malicious activities. Employing intrusion detection systems to monitor wireless communications traffic helps to ensure that the traffic does not contain malicious code prior to transitioning to the wireline network.
GovRAMP crosswalk
Not selected in the imported Snapshot or Core sets. This does not establish exclusion from other GovRAMP baselines.
System and Information Integrity · Enhancement
SI-4(16) · Correlate Monitoring Information
View parent controlControl statement and discussion
NIST control statement
Correlate information from monitoring tools and mechanisms employed throughout the system.
Discussion
Correlating information from different system monitoring tools and mechanisms can provide a more comprehensive view of system activity. Correlating system monitoring tools and mechanisms that typically work in isolation—including malicious code protection software, host monitoring, and network monitoring—can provide an organization-wide monitoring view and may reveal otherwise unseen attack patterns. Understanding the capabilities and limitations of diverse monitoring tools and mechanisms and how to maximize the use of information generated by those tools and mechanisms can help organizations develop, operate, and maintain effective monitoring programs. The correlation of monitoring information is especially important during the transition from older to newer technologies (e.g., transitioning from IPv4 to IPv6 network protocols).
GovRAMP crosswalk
- GovRAMP Moderate Readiness · SI-4 (16) — Direct NIST identifier reference. GovRAMP source matrix
System and Information Integrity · Enhancement
SI-4(17) · Integrated Situational Awareness
View parent controlControl statement and discussion
NIST control statement
Correlate information from monitoring physical, cyber, and supply chain activities to achieve integrated, organization-wide situational awareness.
Discussion
Correlating monitoring information from a more diverse set of information sources helps to achieve integrated situational awareness. Integrated situational awareness from a combination of physical, cyber, and supply chain monitoring activities enhances the capability of organizations to more quickly detect sophisticated attacks and investigate the methods and techniques employed to carry out such attacks. In contrast to [SI-4(16)](#si-4.16) , which correlates the various cyber monitoring information, integrated situational awareness is intended to correlate monitoring beyond the cyber domain. Correlation of monitoring information from multiple activities may help reveal attacks on organizations that are operating across multiple attack vectors.
GovRAMP crosswalk
Not selected in the imported Snapshot or Core sets. This does not establish exclusion from other GovRAMP baselines.
System and Information Integrity · Enhancement
SI-4(18) · Analyze Traffic and Covert Exfiltration
View parent controlControl statement and discussion
NIST control statement
Analyze outbound communications traffic at external interfaces to the system and at the following interior points to detect covert exfiltration of information: [Assignment: interior points].
Discussion
Organization-defined interior points include subnetworks and subsystems. Covert means that can be used to exfiltrate information include steganography.
GovRAMP crosswalk
- GovRAMP Moderate Readiness · SI-4 (18) — Direct NIST identifier reference. GovRAMP source matrix
System and Information Integrity · Enhancement
SI-4(19) · Risk for Individuals
View parent controlControl statement and discussion
NIST control statement
Implement [Assignment: additional monitoring] of individuals who have been identified by [Assignment: sources] as posing an increased level of risk.
Discussion
Indications of increased risk from individuals can be obtained from different sources, including personnel records, intelligence agencies, law enforcement organizations, and other sources. The monitoring of individuals is coordinated with the management, legal, security, privacy, and human resource officials who conduct such monitoring. Monitoring is conducted in accordance with applicable laws, executive orders, directives, regulations, policies, standards, and guidelines.
GovRAMP crosswalk
Not selected in the imported Snapshot or Core sets. This does not establish exclusion from other GovRAMP baselines.
System and Information Integrity · Enhancement
SI-4(20) · Privileged Users
View parent controlControl statement and discussion
NIST control statement
Implement the following additional monitoring of privileged users: [Assignment: additional monitoring].
Discussion
Privileged users have access to more sensitive information, including security-related information, than the general user population. Access to such information means that privileged users can potentially do greater damage to systems and organizations than non-privileged users. Therefore, implementing additional monitoring on privileged users helps to ensure that organizations can identify malicious activity at the earliest possible time and take appropriate actions.
GovRAMP crosswalk
Not selected in the imported Snapshot or Core sets. This does not establish exclusion from other GovRAMP baselines.
System and Information Integrity · Enhancement
SI-4(21) · Probationary Periods
View parent controlControl statement and discussion
NIST control statement
Implement the following additional monitoring of individuals during [Assignment: probationary period]: [Assignment: additional monitoring].
Discussion
During probationary periods, employees do not have permanent employment status within organizations. Without such status or access to information that is resident on the system, additional monitoring can help identify any potentially malicious activity or inappropriate behavior.
GovRAMP crosswalk
Not selected in the imported Snapshot or Core sets. This does not establish exclusion from other GovRAMP baselines.
System and Information Integrity · Enhancement
SI-4(22) · Unauthorized Network Services
View parent controlControl statement and discussion
NIST control statement
(a) Detect network services that have not been authorized or approved by [Assignment: authorization or approval processes] ; and
(b) [Selection (one-or-more): audit; alert [Assignment: personnel or roles] ] when detected.
Discussion
Unauthorized or unapproved network services include services in service-oriented architectures that lack organizational verification or validation and may therefore be unreliable or serve as malicious rogues for valid services.
GovRAMP crosswalk
Not selected in the imported Snapshot or Core sets. This does not establish exclusion from other GovRAMP baselines.
System and Information Integrity · Enhancement
SI-4(23) · Host-based Devices
View parent controlControl statement and discussion
NIST control statement
Implement the following host-based monitoring mechanisms at [Assignment: system components]: [Assignment: host-based monitoring mechanisms].
Discussion
Host-based monitoring collects information about the host (or system in which it resides). System components in which host-based monitoring can be implemented include servers, notebook computers, and mobile devices. Organizations may consider employing host-based monitoring mechanisms from multiple product developers or vendors.
GovRAMP crosswalk
- GovRAMP Moderate Readiness · SI-4 (23) — Direct NIST identifier reference. GovRAMP source matrix
System and Information Integrity · Enhancement
SI-4(24) · Indicators of Compromise
View parent controlControl statement and discussion
NIST control statement
Discover, collect, and distribute to [Assignment: personnel or roles] , indicators of compromise provided by [Assignment: sources].
Discussion
Indicators of compromise (IOC) are forensic artifacts from intrusions that are identified on organizational systems at the host or network level. IOCs provide valuable information on systems that have been compromised. IOCs can include the creation of registry key values. IOCs for network traffic include Universal Resource Locator or protocol elements that indicate malicious code command and control servers. The rapid distribution and adoption of IOCs can improve information security by reducing the time that systems and organizations are vulnerable to the same exploit or attack. Threat indicators, signatures, tactics, techniques, procedures, and other indicators of compromise may be available via government and non-government cooperatives, including the Forum of Incident Response and Security Teams, the United States Computer Emergency Readiness Team, the Defense Industrial Base Cybersecurity Information Sharing Program, and the CERT Coordination Center.
GovRAMP crosswalk
Not selected in the imported Snapshot or Core sets. This does not establish exclusion from other GovRAMP baselines.
System and Information Integrity · Enhancement
SI-4(25) · Optimize Network Traffic Analysis
View parent controlControl statement and discussion
NIST control statement
Provide visibility into network traffic at external and key internal system interfaces to optimize the effectiveness of monitoring devices.
Discussion
Encrypted traffic, asymmetric routing architectures, capacity and latency limitations, and transitioning from older to newer technologies (e.g., IPv4 to IPv6 network protocol transition) may result in blind spots for organizations when analyzing network traffic. Collecting, decrypting, pre-processing, and distributing only relevant traffic to monitoring devices can streamline the efficiency and use of devices and optimize traffic analysis.
GovRAMP crosswalk
Not selected in the imported Snapshot or Core sets. This does not establish exclusion from other GovRAMP baselines.
System and Information Integrity · Base control
SI-5 · Security Alerts, Advisories, and Directives
Control statement and discussion
NIST control statement
a. Receive system security alerts, advisories, and directives from [Assignment: external organizations] on an ongoing basis;
b. Generate internal security alerts, advisories, and directives as deemed necessary;
c. Disseminate security alerts, advisories, and directives to: [Selection (one-or-more): [Assignment: personnel or roles] ; [Assignment: elements] ; [Assignment: external organizations] ] ; and
d. Implement security directives in accordance with established time frames, or notify the issuing organization of the degree of noncompliance.
Discussion
The Cybersecurity and Infrastructure Security Agency (CISA) generates security alerts and advisories to maintain situational awareness throughout the Federal Government. Security directives are issued by OMB or other designated organizations with the responsibility and authority to issue such directives. Compliance with security directives is essential due to the critical nature of many of these directives and the potential (immediate) adverse effects on organizational operations and assets, individuals, other organizations, and the Nation should the directives not be implemented in a timely manner. External organizations include supply chain partners, external mission or business partners, external service providers, and other peer or supporting organizations.
GovRAMP crosswalk
- GovRAMP Moderate Readiness · SI-5 — Direct NIST identifier reference. GovRAMP source matrix
System and Information Integrity · Enhancement
SI-5(1) · Automated Alerts and Advisories
View parent controlControl statement and discussion
NIST control statement
Broadcast security alert and advisory information throughout the organization using [Assignment: automated mechanisms].
Discussion
The significant number of changes to organizational systems and environments of operation requires the dissemination of security-related information to a variety of organizational entities that have a direct interest in the success of organizational mission and business functions. Based on information provided by security alerts and advisories, changes may be required at one or more of the three levels related to the management of risk, including the governance level, mission and business process level, and the information system level.
GovRAMP crosswalk
Not selected in the imported Snapshot or Core sets. This does not establish exclusion from other GovRAMP baselines.
System and Information Integrity · Base control
SI-6 · Security and Privacy Function Verification
Control statement and discussion
NIST control statement
a. Verify the correct operation of [Assignment: organization-defined security and privacy functions];
b. Perform the verification of the functions specified in SI-6a [Selection (one-or-more): [Assignment: system transitional states] ; upon command by user with appropriate privilege; [Assignment: frequency] ];
c. Alert [Assignment: personnel or roles] to failed security and privacy verification tests; and
d. [Selection (one-or-more): shut the system down; restart the system; [Assignment: alternative action(s)] ] when anomalies are discovered.
Discussion
Transitional states for systems include system startup, restart, shutdown, and abort. System notifications include hardware indicator lights, electronic alerts to system administrators, and messages to local computer consoles. In contrast to security function verification, privacy function verification ensures that privacy functions operate as expected and are approved by the senior agency official for privacy or that privacy attributes are applied or used as expected.
GovRAMP crosswalk
- GovRAMP Moderate Readiness · SI-6 — Direct NIST identifier reference. GovRAMP source matrix
System and Information Integrity · Enhancement
SI-6(2) · Automation Support for Distributed Testing
View parent controlControl statement and discussion
NIST control statement
Implement automated mechanisms to support the management of distributed security and privacy function testing.
Discussion
The use of automated mechanisms to support the management of distributed function testing helps to ensure the integrity, timeliness, completeness, and efficacy of such testing.
GovRAMP crosswalk
Not selected in the imported Snapshot or Core sets. This does not establish exclusion from other GovRAMP baselines.
System and Information Integrity · Enhancement
SI-6(3) · Report Verification Results
View parent controlControl statement and discussion
NIST control statement
Report the results of security and privacy function verification to [Assignment: personnel or roles].
Discussion
Organizational personnel with potential interest in the results of the verification of security and privacy functions include systems security officers, senior agency information security officers, and senior agency officials for privacy.
GovRAMP crosswalk
Not selected in the imported Snapshot or Core sets. This does not establish exclusion from other GovRAMP baselines.
System and Information Integrity · Base control
SI-7 · Software, Firmware, and Information Integrity
Control statement and discussion
NIST control statement
a. Employ integrity verification tools to detect unauthorized changes to the following software, firmware, and information: [Assignment: organization-defined software, firmware, and information] ; and
b. Take the following actions when unauthorized changes to the software, firmware, and information are detected: [Assignment: organization-defined actions].
Discussion
Unauthorized changes to software, firmware, and information can occur due to errors or malicious activity. Software includes operating systems (with key internal components, such as kernels or drivers), middleware, and applications. Firmware interfaces include Unified Extensible Firmware Interface (UEFI) and Basic Input/Output System (BIOS). Information includes personally identifiable information and metadata that contains security and privacy attributes associated with information. Integrity-checking mechanisms—including parity checks, cyclical redundancy checks, cryptographic hashes, and associated tools—can automatically monitor the integrity of systems and hosted applications.
GovRAMP crosswalk
- GovRAMP Security Snapshot Readiness · SI-7 — Direct NIST identifier reference. GovRAMP source matrix
- GovRAMP Core Readiness — 60 Controls · SI-7 — Direct NIST identifier reference. GovRAMP source matrix
- GovRAMP Moderate Readiness · SI-7 — Direct NIST identifier reference. GovRAMP source matrix