Skip to content
OpenSmartRoute
Skillv1.0.0

SI-4(21)_probationary-periods

Implement the following additional monitoring of individuals during [organization-defined]: [organization-defined].

by CyberStrikeus(0) 0 installs
Free
Sign in to install

Free account. Installing gives you the manifest plus copy-paste snippets.

See reviews

About

Imported from CyberStrikeus/CyberStrike (.cyberstrike/skill/NIST/SP800-53_rev5/SI_system-and-information-integrity/SI-4(21)_probationary-periods/SKILL.md). Install upstream with npx skills add CyberStrikeus/CyberStrike --skill SI-4(21)_probationary-periods. Copyright stays with the author.

SI-4(21) Probationary Periods

Enhancement of: SI-4

High-Level Description

Family: System and Information Integrity (SI) Framework: NIST SP 800-53 Rev 5

During probationary periods, employees do not have permanent employment status within organizations. Without such status or access to information that is resident on the system, additional monitoring can help identify any potentially malicious activity or inappropriate behavior.

What to Check

  • Verify SI-4(21) Probationary Periods is documented in SSP
  • Confirm control is operating effectively
  • Review evidence of continuous monitoring for SI-4(21)
  • Verify enhancement builds upon base control SI-4

How to Test

Step 1: Review Documentation

Examine the System Security Plan (SSP) and related artifacts for SI-4(21) implementation details. Verify the organization has documented how this control is satisfied.

Step 2: Validate Implementation

# For cloud environments, use cloud-audit-mcp tools
# For on-premises, review system configurations directly

# Example: Check if account management policies exist
grep -r "account.management\|access.control" /etc/security/ 2>/dev/null

Step 3: Test Operating Effectiveness

Verify the control is actively functioning, not just documented. Check logs, configurations, and operational evidence.

Tools

Tool Purpose Usage
cloud-audit-mcp Check integrity monitoring cloud_audit_monitoring
AWS CLI Review GuardDuty/Inspector aws guardduty list-detectors

Remediation Guide

Control Statement

Implement the following additional monitoring of individuals during [organization-defined]: [organization-defined].

Implementation Guidance

During probationary periods, employees do not have permanent employment status within organizations. Without such status or access to information that is resident on the system, additional monitoring can help identify any potentially malicious activity or inappropriate behavior.

Risk Assessment

Finding Severity Impact
SI-4(21) Probationary Periods not implemented High System and Information Integrity
SI-4(21) partially implemented Medium Incomplete System and Information Integrity

CWE Categories

CWE ID Title
CWE-20 Improper Input Validation

References

Checklist

  • Control documented in SSP
  • Implementation evidence collected
  • Operating effectiveness validated
  • Continuous monitoring in place
  • Related controls (AC-18) reviewed

Use it

Copy one of these into your project. Installing also returns the manifest and these snippets.

yaml
targets:
  - https://api.opensmartroute.ai/api/v1/registry/cyberstrikeus-cyberstrike-si-4-21-probationary-periods/manifest   # or paste the manifest below

Manifest

An Open Capability Manifest: the router reads it to know what this does, what it costs and when to pick it.

cyberstrikeus-cyberstrike-si-4-21-probationary-periods.ocm.jsonjson
{
  "ocm": "1",
  "id": "cyberstrikeus-cyberstrike-si-4-21-probationary-periods",
  "kind": "skill",
  "name": "SI-4(21)_probationary-periods",
  "description": "Implement the following additional monitoring of individuals during [organization-defined]: [organization-defined].",
  "publisher": "CyberStrikeus",
  "version": "1.0.0",
  "capabilities": {
    "domains": [
      "general"
    ],
    "tags": [
      "skill-md",
      "nist",
      "sp800-53",
      "rev5",
      "si-4-21",
      "si",
      "enhancement",
      "github"
    ],
    "languages": [
      "en"
    ]
  },
  "quality_prior": 0.6,
  "examples": [
    "Implement the following additional monitoring of individuals during [organization-defined]: [organization-defined]."
  ],
  "primary": false,
  "metadata": {
    "source": {
      "provider": "github",
      "repository": "https://github.com/CyberStrikeus/CyberStrike",
      "path": ".cyberstrike/skill/NIST/SP800-53_rev5/SI_system-and-information-integrity/SI-4(21)_probationary-periods/SKILL.md",
      "ref": "df28ccd3dc6d6c02391169121ee2dcdf4a6a132b",
      "url": "https://github.com/CyberStrikeus/CyberStrike/blob/df28ccd3dc6d6c02391169121ee2dcdf4a6a132b/.cyberstrike/skill/NIST/SP800-53_rev5/SI_system-and-information-integrity/SI-4(21)_probationary-periods/SKILL.md",
      "key": "CyberStrikeus/CyberStrike/.cyberstrike/skill/NIST/SP800-53_rev5/SI_system-and-information-integrity/SI-4(21)_probationary-periods/SKILL.md"
    }
  },
  "instructions": "# SI-4(21) Probationary Periods\n\n> **Enhancement of:** SI-4\n\n## High-Level Description\n\n**Family:** System and Information Integrity (SI)\n**Framework:** NIST SP 800-53 Rev 5\n\nDuring probationary periods, employees do not have permanent employment status within organizations. Without such status or access to information that is resident on the system, additional monitoring can help identify any potentially malicious activity or inappropriate behavior.\n\n## What to Check\n\n- [ ] Verify SI-4(21) Probationary Periods is documented in SSP\n- [ ] Confirm control is operating effectively\n- [ ] Review ev",
  "cost": {
    "context_tokens": 827
  }
}

Fetch it by URL: GET /api/v1/registry/cyberstrikeus-cyberstrike-si-4-21-probationary-periods/manifest?version=1.0.0

Reviews

Star ratings from people who tried it. One review per account; edit yours any time.

No reviews yet. Install it, try it, and be the first to rate it.