id: "SI-07(05)" title: "Automated Response to Integrity Violations" family: "SI" family_name: "System and Information Integrity" sort_id: "si-07.05" priority: "P1" implementation_level: "system" parent: "SI-07" enhancement: True


Statement

Automatically {{ insert: param, si-07.05_odp.01 }} when integrity violations are discovered.

Guidance

Organizations may define different integrity-checking responses by type of information, specific information, or a combination of both. Types of information include firmware, software, and user data. Specific information includes boot firmware for certain types of machines. The automatic implementation of controls within organizational systems includes reversing the changes, halting the system, or triggering audit alerts when unauthorized modifications to critical security files occur.

Assessment Objective

{{ insert: param, si-07.05_odp.01 }} are automatically performed when integrity violations are discovered.

System and information integrity policy

system and information integrity procedures

procedures addressing software, firmware, and information integrity

system design documentation

system configuration settings and associated documentation

integrity verification tools and associated documentation

records of integrity scans

records of integrity checks and responses to integrity violations

audit records

system security plan

other relevant documents or records

Organizational personnel responsible for software, firmware, and/or information integrity

organizational personnel with information security responsibilities

system/network administrators

system developer

Software, firmware, and information integrity verification tools

mechanisms providing an automated response to integrity violations

mechanisms supporting and/or implementing security safeguards to be implemented when integrity violations are discovered