id: "SI-07(08)" title: "Auditing Capability for Significant Events" family: "SI" family_name: "System and Information Integrity" sort_id: "si-07.08" priority: "P1" implementation_level: "system" parent: "SI-07" enhancement: True


Statement

Upon detection of a potential integrity violation, provide the capability to audit the event and initiate the following actions: {{ insert: param, si-07.08_odp.01 }}.

Guidance

Organizations select response actions based on types of software, specific software, or information for which there are potential integrity violations.

Assessment Objective: the capability to audit an event upon the detection of a potential integrity violation is provided;

Assessment Objective: {{ insert: param, si-07.08_odp.01 }} is/are initiated upon the detection of a potential integrity violation.

System and information integrity policy

system and information integrity procedures

procedures addressing software, firmware, and information integrity

system design documentation

system configuration settings and associated documentation

integrity verification tools and associated documentation

records of integrity scans

incident response records

list of security-relevant changes to the system

automated tools supporting alerts and notifications if unauthorized security changes are detected

system audit records

system security plan

other relevant documents or records

Organizational personnel responsible for software, firmware, and/or information integrity

organizational personnel with information security responsibilities

system/network administrators

system developer

Software, firmware, and information integrity verification tools

mechanisms supporting and/or implementing the capability to audit potential integrity violations

mechanisms supporting and/or implementing alerts about potential integrity violations