(a) Detect network services that have not been authorized or approved by [Assignment: authorization or approval processes] ; and
(b) [Selection: organization-defined value] when detected.
Supplemental Guidance
Unauthorized or unapproved network services include services in service-oriented architectures that lack organizational verification or validation and may therefore be unreliable or serve as malicious rogues for valid services.