id: "SI-07(07)" title: "Integration of Detection and Response" family: "SI" family_name: "System and Information Integrity" sort_id: "si-07.07" priority: "P1" implementation_level: "organization" parent: "SI-07" enhancement: True


Statement

Incorporate the detection of the following unauthorized changes into the organizational incident response capability: {{ insert: param, si-07.07_odp }}.

Guidance

Integrating detection and response helps to ensure that detected events are tracked, monitored, corrected, and available for historical purposes. Maintaining historical records is important for being able to identify and discern adversary actions over an extended time period and for possible legal actions. Security-relevant changes include unauthorized changes to established configuration settings or the unauthorized elevation of system privileges.

Assessment Objective

the detection of {{ insert: param, si-07.07_odp }} are incorporated into the organizational incident response capability.

System and information integrity policy

system and information integrity procedures

procedures addressing software, firmware, and information integrity

procedures addressing incident response

system design documentation

system configuration settings and associated documentation

incident response records

audit records

system security plan

other relevant documents or records

Organizational personnel responsible for software, firmware, and/or information integrity

organizational personnel with information security responsibilities

organizational personnel with incident response responsibilities

Organizational processes for incorporating the detection of unauthorized security-relevant changes into the incident response capability

software, firmware, and information integrity verification tools

mechanisms supporting and/or implementing the incorporation of detection of unauthorized security-relevant changes into the incident response capability