Monitoring for Information Disclosure
Description
a. Monitor [organization-defined parameter] [organization-defined parameter] for evidence of unauthorized disclosure of organizational information; and b. If an information disclosure is discovered:
Mapped SPARTA techniques
25 techniques
Mapped by SPARTA, not curated by SafeMode Space.
Mapped by SPARTA, not curated by SafeMode Space.
Mapped by SPARTA, not curated by SafeMode Space.
Mapped by SPARTA, not curated by SafeMode Space.
Mapped by SPARTA, not curated by SafeMode Space.
Mapped by SPARTA, not curated by SafeMode Space.
AU-13 (Monitoring for Information Disclosure) actively detects unauthorized exposure of design information online, narrowing the recon window.
AU-13 detects when FSW-design content (SDKs, architecture diagrams) appears in unauthorized public locations.
AU-13 detects firmware images and bitstreams appearing in unauthorized public locations.
AU-13 detects exposure of cryptographic specifications in unauthorized public locations.
AU-13 detects exposure of bus-architecture documentation in unauthorized public locations.
AU-13 detects exposure of thermal-design materials in unauthorized public locations.
AU-13 detects exposure of payload specifications in unauthorized public locations.
AU-13 detects exposure of fault-management documentation in unauthorized public locations.
AU-13 detects exposure of contact lists, org charts, and role assignments in unauthorized public locations.
AU-13 detects exposure of operational schedules and CONOPS material in unauthorized public locations.
AU-13 detects exposure of frequency plans and link details in unauthorized public locations.
AU-13 detects exposure of communications-equipment inventories in unauthorized public locations.
AU-13 detects exposure of commanding-protocol details in unauthorized public locations.
AU-13 detects exposure of credentials in unauthorized public locations (paste sites, repos, leak forums).
AU-13 detects exposure of FSW development artifacts (SBOMs, toolchains, signing-key locations) in unauthorized public locations.
AU-13 detects exposure of testing-tool inventories or rule sets in unauthorized public locations.
AU-13 detects exposure of safe-mode procedures and indicators in unauthorized public sources.
AU-13 detects exposure of hardware-supply-chain inventories in unauthorized public locations.
AU-13 detects exposure of contractual/operational relationship data in unauthorized public locations.
Cite as SafeMode Space, nist-80053-rev5 AU-13.