Skip to main content
Version: 2.1.1-preview

CISA.MS.EXO.16.2 - Alerts SHOULD be sent to a monitored address or incorporated into a security information and event management (SIEM) system.

Overview

Alerts SHOULD be sent to a monitored address or incorporated into a security information and event management (SIEM) system.

Rationale: Suspicious or malicious events, if not resolved promptly, may have a greater impact to users and the agency. Sending alerts to a monitored email address or SIEM system helps ensure these suspicious or malicious events are acted upon in a timely manner to limit overall impact.

Remediation action:

  1. Sign in to Microsoft 365 Defender.
  2. Select Settings.
  3. Select either:
  4. Ensure a SIEM integration is configured for your organization.

Test Metadata

FieldValue
Test IDCISA.MS.EXO.16.2
SeverityMedium
SuiteCISA
Categoryexchange
PowerShell testTest-MtCisaExoAlertSiem
TagsCISA, CISA.MS.EXO.16.2, MS.EXO, MS.EXO.16.2

Source

  • Pester test: tests/cisa/exchange/Test-MtCisaExoAlertSiem.Tests.ps1
  • PowerShell source: powershell/public/cisa/exchange/Test-MtCisaExoAlertSiem.ps1