id: "SI-07(05)" title: "Automated Response to Integrity Violations" family: "SI" family_name: "System and Information Integrity" sort_id: "si-07.05" priority: "P1" implementation_level: "system" parent: "SI-07" enhancement: True
Statement
Automatically {{ insert: param, si-07.05_odp.01 }} when integrity violations are discovered.
Guidance
Organizations may define different integrity-checking responses by type of information, specific information, or a combination of both. Types of information include firmware, software, and user data. Specific information includes boot firmware for certain types of machines. The automatic implementation of controls within organizational systems includes reversing the changes, halting the system, or triggering audit alerts when unauthorized modifications to critical security files occur.
Assessment Objective
{{ insert: param, si-07.05_odp.01 }} are automatically performed when integrity violations are discovered.
System and information integrity policy
system and information integrity procedures
procedures addressing software, firmware, and information integrity
system design documentation
system configuration settings and associated documentation
integrity verification tools and associated documentation
records of integrity scans
records of integrity checks and responses to integrity violations
audit records
system security plan
other relevant documents or records
Organizational personnel responsible for software, firmware, and/or information integrity
organizational personnel with information security responsibilities
system/network administrators
system developer
Software, firmware, and information integrity verification tools
mechanisms providing an automated response to integrity violations
mechanisms supporting and/or implementing security safeguards to be implemented when integrity violations are discovered