id: "SI-03(10)" title: "Malicious Code Analysis" family: "SI" family_name: "System and Information Integrity" sort_id: "si-03.10" priority: "P1" implementation_level: "organization" parent: "SI-03" enhancement: True


Employ the following tools and techniques to analyze the characteristics and behavior of malicious code: {{ insert: param, si-03.10_odp }} ; and

Incorporate the results from malicious code analysis into organizational incident response and flaw remediation processes.

Guidance

The use of malicious code analysis tools provides organizations with a more in-depth understanding of adversary tradecraft (i.e., tactics, techniques, and procedures) and the functionality and purpose of specific instances of malicious code. Understanding the characteristics of malicious code facilitates effective organizational responses to current and future threats. Organizations can conduct malicious code analyses by employing reverse engineering techniques or by monitoring the behavior of executing code.

Assessment Objective: {{ insert: param, si-03.10_odp }} are employed to analyze the characteristics and behavior of malicious code;

Assessment Objective: the results from malicious code analysis are incorporated into organizational incident response processes;

Assessment Objective: the results from malicious code analysis are incorporated into organizational flaw remediation processes.

System and information integrity policy

system and information integrity procedures

procedures addressing malicious code protection

procedures addressing incident response

procedures addressing flaw remediation

system design documentation

malicious code protection mechanisms, tools, and techniques

system configuration settings and associated documentation

results from malicious code analyses

records of flaw remediation events resulting from malicious code analyses

system audit records

system security plan

other relevant documents or records

System/network administrators

organizational personnel with information security responsibilities

organizational personnel installing, configuring, and/or maintaining the system

organizational personnel responsible for malicious code protection

organizational personnel responsible for flaw remediation

organizational personnel responsible for incident response/management

Organizational process for incident response

organizational process for flaw remediation

mechanisms supporting and/or implementing malicious code protection capabilities

tools and techniques for the analysis of malicious code characteristics and behavior