NIST 800-171 Controls · System and Information Integrity
SI.2.007 — Identify Unauthorized System Use
Identify unauthorized use of organizational systems.
What SI.2.007 means in plain English
You need to be able to spot when someone is using your systems in a way they should not be — whether that is an employee accessing files outside their role, someone logging in at 3 AM from a foreign country, or a program running that nobody installed. Review your audit logs and watch for anomalies. Set up alerts for things like logins from unusual locations, access to sensitive folders by unauthorized accounts, or new software installations. The earlier you catch unauthorized use, the less damage it can do.
The assessment question
“Do you have mechanisms to detect unauthorized use of your systems, such as monitoring for anomalous login patterns, unauthorized file access, unapproved software installations, and off-hours activity?”
How to implement SI.2.007
- Enable Windows audit logging via Group Policy: Computer Configuration > Windows Settings > Security Settings > Advanced Audit Policy Configuration > enable Logon/Logoff, Object Access, and Account Management audit events.
- In Microsoft 365, enable Unified Audit Logging in the Compliance Center: search.compliance.microsoft.com > Audit > verify auditing is turned on. This logs all user activity in email, SharePoint, and Teams.
- Create alerts for suspicious patterns: in Microsoft 365 Security Center, set up alert policies for impossible travel activity, mass file downloads, and logins from unfamiliar locations.
- Review Windows Security Event logs weekly for Event ID 4624 (successful logon) at unusual hours and Event ID 4663 (file access) to sensitive CUI folders.
- Maintain a baseline of normal system usage (who logs in when, what software runs, typical data transfer volumes) so you can spot deviations.
Evidence your assessor will ask for
- Audit logging configuration showing relevant events are captured (logon, file access, account changes)
- Evidence of regular audit log review (weekly review notes or automated alert reports)
- Alert policy configuration for suspicious activity patterns
- Examples of detected unauthorized use and response actions taken (if any occurred)
- Written procedure for detecting and responding to unauthorized system use
Does AI prompt monitoring help with this control? It supports it.
AI prompt monitoring does not satisfy SI.2.007 on its own, but its output feeds the capability this control requires: the tamper-evident event stream of allowed and blocked AI prompts becomes detection signal, incident record, and reviewable audit material. Treat the AI firewall as one input to this practice, alongside the remediation steps above.
Full mapping: which 800-171 controls AI prompt monitoring evidences →
More System and Information Integrity controls
Score yourself against all 110 controls
The free ShieldReady assessment walks every NIST 800-171 requirement, computes your SPRS score, and shows exactly which gaps cost the most points.