Publication of Supplemental Monitoring Guidance, v1.0

Specifies requirements in accordance with the DHS CISA Secure-by-Design Pledge, published by the U.S. Dept of Homeland Security (DHS) Cybersecurity and Infrastructure Agency (CISA). Requires an organization to publish monitoring guidance for products that lack a cybersecurity incident logging capability, across all of its product and service offerings.

Assessment Step

1
Publication of Supplemental Monitoring Guidance (PublicationofSupplementalMonitoringGuidance)
Across all of its product and service offerings, does the organization publish monitoring guidance for products that lack a cybersecurity incident logging capability?
Artifact
A1
Provide evidence (e.g. organizational policies, procedures, compliance/assessment reports, etc.) and supporting notes as appropriate to support the assessor's response to this assessment step.

Conformance Criteria (1)

Publication of Supplemental Monitoring Guidance
Across all of its product and service offerings, the organization must publish monitoring guidance for products that lack a cybersecurity incident logging capability.
Citation
SBDP
(doc)