36 MAC Pt. 1, R. 17.1
System and Information Integrity
Cite as 36 Miss. Admin. Code Pt. 1, R. 17.1
System and Information Integrity
A. Each agency must identify, report, and correct system flaws in a timely manner.
B. Each agency must monitor, control, and protect communications.
1. Establish and maintain a documented vulnerability management and
remediation process for enterprise assets. Review and update documentation
annually, or when significant enterprise changes occur that could impact this
Safeguard.
2. Remediate detected vulnerabilities in software through processes and tooling
on a monthly, or more frequent basis, based on the remediation process.
C. Each agency must provide protection from malware at designated locations within
organizational systems.
1. Deploy and maintain anti-malware software on all enterprise assets, where
appropriate and/or supported. Further, agencies should deploy anti-malware
scanning at the network level to include, at a minimum, the network external
boundary.
D. Each agency must monitor system security alerts and advisories and take action in
response.
1. Centralize security event alerting across enterprise assets for log correlation
and analysis. Best practice implementation requires the use of a SIEM, which
includes vendor-defined event correlation alerts. A log analytics platform
configured with security-relevant correlation alerts also satisfies this
Safeguard.
E. Each agency must update malware protection mechanisms when new releases are
available.
1. Configure automatic updates for anti-malware signature files on all enterprise
assets.
F. Each agency must perform periodic scans of organizational systems on a weekly basis
at minimum, and real-time scans of files from external sources as files are
downloaded, opened, or executed.
1. Configure anti-malware software to automatically scan removable media.
G. Each agency must monitor agency systems, including inbound and outbound
communications traffic, to detect attacks and indicators of potential attacks.
1. Deploy a host-based intrusion detection solution on enterprise assets, where
appropriate and/or supported.
2. Deploy a network intrusion detection solution on enterprise assets, where
appropriate. Example implementations include the use of a Network Intrusion
Detection System (NIDS) or equivalent cloud service provider (CSP) service.
H. Each agency must identify unauthorized use of agency systems via aggregating user
logins and other system events and reviewing them on a consistent basis or
immediately upon identifying a potential or realized security event.