|
controlSI-7
Software, Firmware, and Information Integrity (SI-7)
Employ integrity verification tools to detect unauthorized changes to the following software, firmware, and information: [organization-defined] ; and Take the following actions when unauthorized changes to the software, firmware, and information are detected: [organization-defined].
Security Baselines
MODERATEHIGHLOW
integritymalwareflaw-remediationmonitoring
Why These Connect
Baselined In2
This control is included in the linked security baseline (LOW, MODERATE, or HIGH).
Supports62
These related controls work together — a change to one may affect the others.
Mitigates12
This control helps defend against or reduce the risk of the linked threat technique.
Enhances17
These enhancements add specific capabilities or refinements to the base control.
Related Controls(39)
AU-2Event Logging (AU-2)
LMH
AU-3Content of Audit Records (AU-3)LMH
AU-6Audit Record Review, Analysis, and Reporting (AU-6)LMH
AU-12Audit Record Generation (AU-12)LMH
CM-3Configuration Change Control (CM-3)MH
CM-11User-installed Software (CM-11)LMH
CM-12Information Location (CM-12)MH
CM-14Signed Components (CM-14)IR-4Incident Handling (IR-4)LMH
IR-5Incident Monitoring (IR-5)LMH
RA-5Vulnerability Monitoring and Scanning (RA-5)LMH
SA-24Design For Cyber Resiliency (SA-24)SC-12Cryptographic Key Establishment and Management (SC-12)LMH
SC-13Cryptographic Protection (SC-13)LMH
SC-28Protection of Information at Rest (SC-28)MH
SC-34Non-modifiable Executable Programs (SC-34)SC-37Out-of-band Channels (SC-37)SC-44Detonation Chambers (SC-44)SI-2Flaw Remediation (SI-2)LMH
SI-3Malicious Code Protection (SI-3)LMH
SI-4System Monitoring (SI-4)LMH
SI-6Security and Privacy Function Verification (SI-6)H
AC-4Information Flow Enforcement (AC-4)MH
CM-7Least Functionality (CM-7)LMH
CM-8System Component Inventory (CM-8)LMH
MA-3Maintenance Tools (MA-3)MH
MA-4Nonlocal Maintenance (MA-4)LMH
SA-8Security and Privacy Engineering Principles (SA-8)LMH
SA-9External System Services (SA-9)LMH
SA-10Developer Configuration Management (SA-10)MH
SC-8Transmission Confidentiality and Integrity (SC-8)MH
SR-3Supply Chain Controls and Processes (SR-3)LMH
SR-4Provenance (SR-4)SR-5Acquisition Strategies, Tools, and Methods (SR-5)LMH
SR-6Supplier Assessments and Reviews (SR-6)MH
SR-9Tamper Resistance and Detection (SR-9)H
SR-10Inspection of Systems or Components (SR-10)LMH
SR-11Component Authenticity (SR-11)LMH
SI-16Memory Protection (SI-16)MH
Threat Coverage(12 ATT&CK techniques)
T1190Exploit Public-Facing ApplicationT1059Command and Scripting InterpreterT1203Exploitation for Client ExecutionT1547Boot or Logon Autostart ExecutionT1505Server Software ComponentT1068Exploitation for Privilege EscalationT1027Obfuscated Files or InformationT1562Impair DefensesT1036MasqueradingT1112Modify RegistryT1110Brute ForceT1486Data Encrypted for Impact
Control Enhancements(17)
SI-7(1)Integrity Checks (SI-7(1))
MH
SI-7(2)Automated Notifications of Integrity Violations (SI-7(2))H
SI-7(3)Centrally Managed Integrity Tools (SI-7(3))SI-7(4)Tamper-evident Packaging (SI-7(4))WSI-7(5)Automated Response to Integrity Violations (SI-7(5))H
SI-7(6)Cryptographic Protection (SI-7(6))SI-7(7)Integration of Detection and Response (SI-7(7))MH
SI-7(8)Auditing Capability for Significant Events (SI-7(8))SI-7(9)Verify Boot Process (SI-7(9))SI-7(10)Protection of Boot Firmware (SI-7(10))SI-7(11)Confined Environments with Limited Privileges (SI-7(11))WSI-7(12)Integrity Verification (SI-7(12))SI-7(13)Code Execution in Protected Environments (SI-7(13))WSI-7(14)Binary or Machine Executable Code (SI-7(14))WSI-7(15)Code Authentication (SI-7(15))H
SI-7(16)Time Limit on Process Execution Without Supervision (SI-7(16))SI-7(17)Runtime Application Self-protection (SI-7(17))