NIST 800-53 Rev. 5

SI-4(20): System Monitoring | Privileged Users

Control Text:

Implement the following additional monitoring of privileged users: [Assignment: organization-defined additional monitoring].

Privileged users have access to more sensitive information, including security-related information, than the general user population. Access to such information means that privileged users can potentially do greater damage to systems and organizations than non-privileged users. Therefore, implementing additional monitoring on privileged users helps to ensure that organizations can identify malicious activity at the earliest possible time and take appropriate actions.

Related Controls