id: "SI-07(08)" title: "Auditing Capability for Significant Events" family: "SI" family_name: "System and Information Integrity" sort_id: "si-07.08" priority: "P1" implementation_level: "system" parent: "SI-07" enhancement: True
Statement
Upon detection of a potential integrity violation, provide the capability to audit the event and initiate the following actions: {{ insert: param, si-07.08_odp.01 }}.
Guidance
Organizations select response actions based on types of software, specific software, or information for which there are potential integrity violations.
Assessment Objective: the capability to audit an event upon the detection of a potential integrity violation is provided;
Assessment Objective: {{ insert: param, si-07.08_odp.01 }} is/are initiated upon the detection of a potential integrity violation.
System and information integrity policy
system and information integrity procedures
procedures addressing software, firmware, and information integrity
system design documentation
system configuration settings and associated documentation
integrity verification tools and associated documentation
records of integrity scans
incident response records
list of security-relevant changes to the system
automated tools supporting alerts and notifications if unauthorized security changes are detected
system audit records
system security plan
other relevant documents or records
Organizational personnel responsible for software, firmware, and/or information integrity
organizational personnel with information security responsibilities
system/network administrators
system developer
Software, firmware, and information integrity verification tools
mechanisms supporting and/or implementing the capability to audit potential integrity violations
mechanisms supporting and/or implementing alerts about potential integrity violations