|
controlSI-7

Software, Firmware, and Information Integrity (SI-7)

Employ integrity verification tools to detect unauthorized changes to the following software, firmware, and information: [organization-defined] ; and Take the following actions when unauthorized changes to the software, firmware, and information are detected: [organization-defined].

Security Baselines

MODERATEHIGHLOW
integritymalwareflaw-remediationmonitoring

Why These Connect

Baselined In2

This control is included in the linked security baseline (LOW, MODERATE, or HIGH).

Supports62

These related controls work together — a change to one may affect the others.

Mitigates12

This control helps defend against or reduce the risk of the linked threat technique.

Enhances17

These enhancements add specific capabilities or refinements to the base control.

Related Controls(39)

AU-2Event Logging (AU-2)
LMH
AU-3Content of Audit Records (AU-3)
LMH
AU-6Audit Record Review, Analysis, and Reporting (AU-6)
LMH
AU-12Audit Record Generation (AU-12)
LMH
CM-3Configuration Change Control (CM-3)
MH
CM-11User-installed Software (CM-11)
LMH
CM-12Information Location (CM-12)
MH
CM-14Signed Components (CM-14)IR-4Incident Handling (IR-4)
LMH
IR-5Incident Monitoring (IR-5)
LMH
RA-5Vulnerability Monitoring and Scanning (RA-5)
LMH
SA-24Design For Cyber Resiliency (SA-24)SC-12Cryptographic Key Establishment and Management (SC-12)
LMH
SC-13Cryptographic Protection (SC-13)
LMH
SC-28Protection of Information at Rest (SC-28)
MH
SC-34Non-modifiable Executable Programs (SC-34)SC-37Out-of-band Channels (SC-37)SC-44Detonation Chambers (SC-44)SI-2Flaw Remediation (SI-2)
LMH
SI-3Malicious Code Protection (SI-3)
LMH
SI-4System Monitoring (SI-4)
LMH
SI-6Security and Privacy Function Verification (SI-6)
H
AC-4Information Flow Enforcement (AC-4)
MH
CM-7Least Functionality (CM-7)
LMH
CM-8System Component Inventory (CM-8)
LMH
MA-3Maintenance Tools (MA-3)
MH
MA-4Nonlocal Maintenance (MA-4)
LMH
SA-8Security and Privacy Engineering Principles (SA-8)
LMH
SA-9External System Services (SA-9)
LMH
SA-10Developer Configuration Management (SA-10)
MH
SC-8Transmission Confidentiality and Integrity (SC-8)
MH
SR-3Supply Chain Controls and Processes (SR-3)
LMH
SR-4Provenance (SR-4)SR-5Acquisition Strategies, Tools, and Methods (SR-5)
LMH
SR-6Supplier Assessments and Reviews (SR-6)
MH
SR-9Tamper Resistance and Detection (SR-9)
H
SR-10Inspection of Systems or Components (SR-10)
LMH
SR-11Component Authenticity (SR-11)
LMH
SI-16Memory Protection (SI-16)
MH

Control Enhancements(17)