CLAUDE CODE MARKETPLACES
SkillsCyberStrikeus/CyberStrikeAU-13(1)_use-of-automated-tools

AU-13(1)_use-of-automated-tools

Monitor open-source information and information sites using [organization-defined].

npx skills add https://github.com/CyberStrikeus/CyberStrike --skill AU-13(1)_use-of-automated-tools
SKILL.md

AU-13(1) Use of Automated Tools

Enhancement of: AU-13

High-Level Description

Family: Audit and Accountability (AU) Framework: NIST SP 800-53 Rev 5

Automated mechanisms include commercial services that provide notifications and alerts to organizations and automated scripts to monitor new posts on websites.

What to Check

  • Verify AU-13(1) Use of Automated Tools is documented in SSP
  • Confirm control is operating effectively
  • Review evidence of continuous monitoring for AU-13(1)
  • Verify enhancement builds upon base control AU-13

How to Test

Step 1: Review Documentation

Examine the System Security Plan (SSP) and related artifacts for AU-13(1) implementation details. Verify the organization has documented how this control is satisfied.

Step 2: Validate Implementation

# For cloud environments, use cloud-audit-mcp tools
# For on-premises, review system configurations directly

# Example: Check if account management policies exist
grep -r "account.management\|access.control" /etc/security/ 2>/dev/null

Step 3: Test Operating Effectiveness

Verify the control is actively functioning, not just documented. Check logs, configurations, and operational evidence.

Tools

ToolPurposeUsage
cloud-audit-mcpCheck logging configurationcloud_audit_logging
AWS CLIReview CloudTrail/CloudWatchaws cloudtrail describe-trails

Remediation Guide

Control Statement

Monitor open-source information and information sites using [organization-defined].

Implementation Guidance

Automated mechanisms include commercial services that provide notifications and alerts to organizations and automated scripts to monitor new posts on websites.

Risk Assessment

FindingSeverityImpact
AU-13(1) Use of Automated Tools not implementedMediumAudit and Accountability
AU-13(1) partially implementedLowIncomplete Audit and Accountability

CWE Categories

CWE IDTitle
CWE-778Insufficient Logging

References

Checklist

  • Control documented in SSP
  • Implementation evidence collected
  • Operating effectiveness validated
  • Continuous monitoring in place
  • Related controls (none) reviewed