← Browse

@cyberstrikeus/au-13-1-use-of-automated-tools

B

Monitor open-source information and information sites using [organization-defined].

skillclaude

Install

agr install @cyberstrikeus/au-13-1-use-of-automated-tools --target claude

Writes 1 file into .claude/skills/, pinned to git-d4bf6b02.

  • .claude/skills/au-13-1-use-of-automated-tools/SKILL.md

Document


name: "AU-13(1)_use-of-automated-tools" description: "Monitor open-source information and information sites using [organization-defined]." category: "information-gathering" version: "5.2.0" author: "cyberstrike-official" tags:

  • nist
  • sp800-53
  • rev5
  • au-13-1
  • au
  • enhancement tech_stack:
  • aws
  • azure
  • gcp
  • linux
  • windows cwe_ids:
  • CWE-778 chains_with: [] prerequisites:
  • AU-13 severity_boost: {}

AU-13(1) Use of Automated Tools

Enhancement of: AU-13

High-Level Description

Family: Audit and Accountability (AU) Framework: NIST SP 800-53 Rev 5

Automated mechanisms include commercial services that provide notifications and alerts to organizations and automated scripts to monitor new posts on websites.

What to Check

  • Verify AU-13(1) Use of Automated Tools is documented in SSP
  • Confirm control is operating effectively
  • Review evidence of continuous monitoring for AU-13(1)
  • Verify enhancement builds upon base control AU-13

How to Test

Step 1: Review Documentation

Examine the System Security Plan (SSP) and related artifacts for AU-13(1) implementation details. Verify the organization has documented how this control is satisfied.

Step 2: Validate Implementation

# For cloud environments, use cloud-audit-mcp tools
# For on-premises, review system configurations directly

# Example: Check if account management policies exist
grep -r "account.management\|access.control" /etc/security/ 2>/dev/null

Step 3: Test Operating Effectiveness

Verify the control is actively functioning, not just documented. Check logs, configurations, and operational evidence.

Tools

ToolPurposeUsage
cloud-audit-mcpCheck logging configurationcloud_audit_logging
AWS CLIReview CloudTrail/CloudWatchaws cloudtrail describe-trails

Remediation Guide

Control Statement

Monitor open-source information and information sites using [organization-defined].

Implementation Guidance

Automated mechanisms include commercial services that provide notifications and alerts to organizations and automated scripts to monitor new posts on websites.

Risk Assessment

FindingSeverityImpact
AU-13(1) Use of Automated Tools not implementedMediumAudit and Accountability
AU-13(1) partially implementedLowIncomplete Audit and Accountability

CWE Categories

CWE IDTitle
CWE-778Insufficient Logging

References

Checklist

  • Control documented in SSP
  • Implementation evidence collected
  • Operating effectiveness validated
  • Continuous monitoring in place
  • Related controls (none) reviewed

Trustgrade B

  • passBody integrity

    Whether the stored document is plausibly the kind of file the artifact declares, rather than something fetched by mistake.

  • passType matchnot applicable to this artifact type

    Whether the artifact is really the kind of thing its metadata claims it is.

  • passFreshness

    How long since the source repository was last pushed to.

  • passPrompt injection

    Scans the artifact's own text for instructions aimed at your agent rather than at you.

  • warnLicensecopyleft/unknown — index-and-link only

    Whether the source repository declares an SPDX license permissive enough to redistribute.

How the grade is calculated

Each check contributes 0 points when it passes, 1 when it warns, and 2 when it fails. The total maps to a letter:

  • Aevery check passed
  • Bone warning
  • Ctwo warnings
  • Dprompt injection or body integrity failed, or three warnings
  • Fone of those failed, and something else is wrong

These are automated hygiene checks, not a security audit, and not a dependency or vulnerability scan. A grade of A means nothing was flagged — not that the artifact is safe.

Versions

  • git-d4bf6b02fccd2026-07-31