|
controlSI-7

Software, Firmware, and Information Integrity (SI-7)

Employ integrity verification tools to detect unauthorized changes to the following software, firmware, and information: [organization-defined] ; and Take the following actions when unauthorized changes to the software, firmware, and information are detected: [organization-defined].

Security Baselines

MODERATEHIGHLOW
integritymalwareflaw-remediationmonitoring

Why These Connect

Maps To13

These are equivalent or closely aligned requirements in other frameworks.

Baselined In2

This control is included in the linked security baseline (LOW, MODERATE, or HIGH).

Supports62

These related controls work together — a change to one may affect the others.

Mitigates12

This control helps defend against or reduce the risk of the linked threat technique.

Enhances17

These enhancements add specific capabilities or refinements to the base control.

Related Controls(39)

AU-2Event Logging (AU-2)
LMH
AU-3Content of Audit Records (AU-3)
LMH
AU-6Audit Record Review, Analysis, and Reporting (AU-6)
LMH
AU-12Audit Record Generation (AU-12)
LMH
CM-3Configuration Change Control (CM-3)
MH
CM-11User-installed Software (CM-11)
LMH
CM-12Information Location (CM-12)
MH
CM-14Signed Components (CM-14)IR-4Incident Handling (IR-4)
LMH
IR-5Incident Monitoring (IR-5)
LMH
RA-5Vulnerability Monitoring and Scanning (RA-5)
LMH
SA-24Design For Cyber Resiliency (SA-24)SC-12Cryptographic Key Establishment and Management (SC-12)
LMH
SC-13Cryptographic Protection (SC-13)
LMH
SC-28Protection of Information at Rest (SC-28)
MH
SC-34Non-modifiable Executable Programs (SC-34)SC-37Out-of-band Channels (SC-37)SC-44Detonation Chambers (SC-44)SI-2Flaw Remediation (SI-2)
LMH
SI-3Malicious Code Protection (SI-3)
LMH
SI-4System Monitoring (SI-4)
LMH
SI-6Security and Privacy Function Verification (SI-6)
H
AC-4Information Flow Enforcement (AC-4)
MH
CM-7Least Functionality (CM-7)
LMH
CM-8System Component Inventory (CM-8)
LMH
MA-3Maintenance Tools (MA-3)
MH
MA-4Nonlocal Maintenance (MA-4)
LMH
SA-8Security and Privacy Engineering Principles (SA-8)
LMH
SA-9External System Services (SA-9)
LMH
SA-10Developer Configuration Management (SA-10)
MH
SC-8Transmission Confidentiality and Integrity (SC-8)
MH
SR-3Supply Chain Controls and Processes (SR-3)
LMH
SR-4Provenance (SR-4)SR-5Acquisition Strategies, Tools, and Methods (SR-5)
LMH
SR-6Supplier Assessments and Reviews (SR-6)
MH
SR-9Tamper Resistance and Detection (SR-9)
H
SR-10Inspection of Systems or Components (SR-10)
LMH
SR-11Component Authenticity (SR-11)
LMH
SI-16Memory Protection (SI-16)
MH

Cross-Framework Mappings(13)

ID.RA-09ID.RA-09Final
NIST OLIR informative reference — Cybersecurity Framework v2.0 to SP 800-53 Rev 5
PR.DS-01PR.DS-01Final
NIST OLIR informative reference — Cybersecurity Framework v2.0 to SP 800-53 Rev 5
PR.DS-02PR.DS-02Final
NIST OLIR informative reference — Cybersecurity Framework v2.0 to SP 800-53 Rev 5
PR.DS-10PR.DS-10Final
NIST OLIR informative reference — Cybersecurity Framework v2.0 to SP 800-53 Rev 5
PR.PS-02PR.PS-02Final
NIST OLIR informative reference — Cybersecurity Framework v2.0 to SP 800-53 Rev 5
DE.CM-09DE.CM-09Final
NIST OLIR informative reference — Cybersecurity Framework v2.0 to SP 800-53 Rev 5
HIPAAHIPAA Security Rule3 mappingsFinal
NIST OLIR informative reference — HIPAA Security Rule to SP 800-53 Rev 5
ID.RA-09ID.RA-09Final
NIST OLIR informative reference — Cybersecurity Framework v2.0 to SP 800-53 Rev 5
PR.DS-01PR.DS-01Final
NIST OLIR informative reference — Cybersecurity Framework v2.0 to SP 800-53 Rev 5
PR.DS-02PR.DS-02Final
NIST OLIR informative reference — Cybersecurity Framework v2.0 to SP 800-53 Rev 5
PR.DS-10PR.DS-10Final
NIST OLIR informative reference — Cybersecurity Framework v2.0 to SP 800-53 Rev 5
PR.PS-02PR.PS-02Final
NIST OLIR informative reference — Cybersecurity Framework v2.0 to SP 800-53 Rev 5
DE.CM-09DE.CM-09Final
NIST OLIR informative reference — Cybersecurity Framework v2.0 to SP 800-53 Rev 5

Organization-Defined Parameters(6)

Assignmentorganization-defined software
Assignmentorganization-defined firmware
Assignmentorganization-defined information
Assignmentorganization-defined actions
Assignmentorganization-defined actions
Assignmentorganization-defined actions

Control Enhancements(17)