id: "SI-03(10)" title: "Malicious Code Analysis" family: "SI" family_name: "System and Information Integrity" sort_id: "si-03.10" priority: "P1" implementation_level: "organization" parent: "SI-03" enhancement: True
Employ the following tools and techniques to analyze the characteristics and behavior of malicious code: {{ insert: param, si-03.10_odp }} ; and
Incorporate the results from malicious code analysis into organizational incident response and flaw remediation processes.
Guidance
The use of malicious code analysis tools provides organizations with a more in-depth understanding of adversary tradecraft (i.e., tactics, techniques, and procedures) and the functionality and purpose of specific instances of malicious code. Understanding the characteristics of malicious code facilitates effective organizational responses to current and future threats. Organizations can conduct malicious code analyses by employing reverse engineering techniques or by monitoring the behavior of executing code.
Assessment Objective: {{ insert: param, si-03.10_odp }} are employed to analyze the characteristics and behavior of malicious code;
Assessment Objective: the results from malicious code analysis are incorporated into organizational incident response processes;
Assessment Objective: the results from malicious code analysis are incorporated into organizational flaw remediation processes.
System and information integrity policy
system and information integrity procedures
procedures addressing malicious code protection
procedures addressing incident response
procedures addressing flaw remediation
system design documentation
malicious code protection mechanisms, tools, and techniques
system configuration settings and associated documentation
results from malicious code analyses
records of flaw remediation events resulting from malicious code analyses
system audit records
system security plan
other relevant documents or records
System/network administrators
organizational personnel with information security responsibilities
organizational personnel installing, configuring, and/or maintaining the system
organizational personnel responsible for malicious code protection
organizational personnel responsible for flaw remediation
organizational personnel responsible for incident response/management
Organizational process for incident response
organizational process for flaw remediation
mechanisms supporting and/or implementing malicious code protection capabilities
tools and techniques for the analysis of malicious code characteristics and behavior