id: "SI-07(06)" title: "Cryptographic Protection" family: "SI" family_name: "System and Information Integrity" sort_id: "si-07.06" priority: "P1" implementation_level: "system" parent: "SI-07" enhancement: True


Statement

Implement cryptographic mechanisms to detect unauthorized changes to software, firmware, and information.

Guidance

Cryptographic mechanisms used to protect integrity include digital signatures and the computation and application of signed hashes using asymmetric cryptography, protecting the confidentiality of the key used to generate the hash, and using the public key to verify the hash information. Organizations that employ cryptographic mechanisms also consider cryptographic key management solutions.

Assessment Objective: cryptographic mechanisms are implemented to detect unauthorized changes to software;

Assessment Objective: cryptographic mechanisms are implemented to detect unauthorized changes to firmware;

Assessment Objective: cryptographic mechanisms are implemented to detect unauthorized changes to information.

System and information integrity policy

system and information integrity procedures

procedures addressing software, firmware, and information integrity

system design documentation

system configuration settings and associated documentation

cryptographic mechanisms and associated documentation

records of detected unauthorized changes to software, firmware, and information

system audit records

system security plan

other relevant documents or records

Organizational personnel responsible for software, firmware, and/or information integrity

organizational personnel with information security responsibilities

system/network administrators

system developer

Software, firmware, and information integrity verification tools

cryptographic mechanisms implementing software, firmware, and information integrity