SI-4 System and Information Integrity

Information System Monitoring

High Risk Complex Medium Cost

SI-4 requires monitoring the system to detect attacks and indicators of potential attacks, unauthorized local/network/remote connections, and unauthorized use; identifying unauthorized use; deploying monitoring devices strategically; and protecting monitoring information. It is the continuous detection layer that feeds AU-6 review and IR-4 handling for ePHI environments.

Control Objective

Detect malicious or unauthorized activity affecting systems with ePHI in near real time through strategically deployed monitoring and alerting.

Implementation Guidance

  1. Deploy monitoring across endpoints (EDR), network (IDS/NSM), identity (IdP risk), cloud (CSPM/logs), and critical apps (EHR audit feeds).
  2. Define use cases: ransomware behavior, brute force, mass ePHI export, privilege escalation, lateral movement, and geo-impossible logons.
  3. Centralize telemetry in a SIEM or equivalent with retention aligned to policy.
  4. Protect monitoring systems from tampering (separate admin, integrity controls).
  5. Tune to reduce noise; document silenced alerts.
  6. Ensure 24x7 response path for critical alerts (ties to IR-4/IR-6).
  7. Cover remote access and BA connections in monitoring scope.
  8. Review monitoring coverage when new systems join CM-8 inventory.

Real-World Use Cases

How this control shows up in healthcare and HIPAA-covered environments.

EDR detects encryption behavior on a file server

SI-4 alert pages on-call within minutes; IR-4 isolates host and begins CP recovery assessment.

Impossible travel on an EHR admin account

IdP risk + SIEM correlation flags US then overseas logons; sessions revoked under AC-12 and credentials reset.

Silent clinic subnet without sensors

Coverage review finds a new wing without EDR. CM-8/SI-4 gap closure deploys agents before go-live of additional workstations.

Best Practices

  • Use-case driven detection, not only log collection.
  • Protect the monitoring plane itself.
  • Coverage maps tied to asset inventory.
  • On-call response for critical alerts.
  • Regular tuning and purple-team tests.
  • Include cloud and identity signals.

Common Gaps & Violations

  • SIEM collects logs but no detection content.
  • Critical clinics without EDR.
  • Alerts only emailed to a shared inbox nobody watches.
  • Monitoring consoles use shared admin passwords.
  • New systems added without monitoring onboarding.

Required Documentation

  • System monitoring strategy / use-case catalog
  • Sensor coverage map
  • Alerting and on-call procedures
  • Retention settings for monitoring data
  • Tuning / exception records

How to Test & Validate

  1. Validate EDR/IDS coverage % on ePHI assets.
  2. Fire a controlled test detection; confirm alert and response.
  3. Review use-case list against recent threats.
  4. Confirm monitoring admin access is tightly controlled.
  5. Check onboarding checklist includes monitoring for new systems.

Audit Considerations

HIPAA activity review and malware protections are stronger with SI-4 evidence. Show coverage, alert examples, and response linkage — not only tool licenses.

HIPAA Mapping

How this NIST control supports HIPAA Security Rule expectations.

  • 164.308(a)(1)(ii)(D) Information System Activity Review — monitoring supports regular review of system activity.
  • 164.308(a)(5)(ii)(B) Protection from Malicious Software — detection mechanisms help guard against malware.
  • 164.312(b) Audit Controls — monitoring often consumes and analyzes audit events.
  • 164.308(a)(6) Security Incident Procedures — monitoring detects incidents to handle/report.

Compliance Tips

  • Add 'monitoring onboarded' to every production change checklist.
  • Start with a small set of high-fidelity ransomware and mass-export detections.
  • Report coverage gaps as formal risks in RA-3 until closed.

Frequently Asked Questions

Is antivirus alone enough for SI-4?

No. SI-4 expects broader monitoring for attacks and unauthorized use across the system — EDR, logs, network/identity signals, etc.

How does SI-4 relate to AU-6?

SI-4 emphasizes ongoing system monitoring/detection; AU-6 emphasizes review/analysis/reporting of audit records. They work together.

Do we need 24x7 SOC?

Define monitoring response appropriate to risk — many clinics use MSSP/on-call for critical alerts even without a full SOC.

References & Resources

  • NIST SP 800-53 Rev. 5 — SI-4
  • NIST SP 800-94 Guide to Intrusion Detection and Prevention
  • Related controls: AU-6, IR-4, RA-5, AC-17, SI-3

Need Help Implementing SI-4?

Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.