id: "SI-07(07)" title: "Integration of Detection and Response" family: "SI" family_name: "System and Information Integrity" sort_id: "si-07.07" priority: "P1" implementation_level: "organization" parent: "SI-07" enhancement: True
Statement
Incorporate the detection of the following unauthorized changes into the organizational incident response capability: {{ insert: param, si-07.07_odp }}.
Guidance
Integrating detection and response helps to ensure that detected events are tracked, monitored, corrected, and available for historical purposes. Maintaining historical records is important for being able to identify and discern adversary actions over an extended time period and for possible legal actions. Security-relevant changes include unauthorized changes to established configuration settings or the unauthorized elevation of system privileges.
Assessment Objective
the detection of {{ insert: param, si-07.07_odp }} are incorporated into the organizational incident response capability.
System and information integrity policy
system and information integrity procedures
procedures addressing software, firmware, and information integrity
procedures addressing incident response
system design documentation
system configuration settings and associated documentation
incident response records
audit records
system security plan
other relevant documents or records
Organizational personnel responsible for software, firmware, and/or information integrity
organizational personnel with information security responsibilities
organizational personnel with incident response responsibilities
Organizational processes for incorporating the detection of unauthorized security-relevant changes into the incident response capability
software, firmware, and information integrity verification tools
mechanisms supporting and/or implementing the incorporation of detection of unauthorized security-relevant changes into the incident response capability