id: "SI-07(17)" title: "Runtime Application Self-protection" family: "SI" family_name: "System and Information Integrity" sort_id: "si-07.17" priority: "P1" implementation_level: "system" parent: "SI-07" enhancement: True
Statement
Implement {{ insert: param, si-07.17_odp }} for application self-protection at runtime.
Guidance
Runtime application self-protection employs runtime instrumentation to detect and block the exploitation of software vulnerabilities by taking advantage of information from the software in execution. Runtime exploit prevention differs from traditional perimeter-based protections such as guards and firewalls which can only detect and block attacks by using network information without contextual awareness. Runtime application self-protection technology can reduce the susceptibility of software to attacks by monitoring its inputs and blocking those inputs that could allow attacks. It can also help protect the runtime environment from unwanted changes and tampering. When a threat is detected, runtime application self-protection technology can prevent exploitation and take other actions (e.g., sending a warning message to the user, terminating the user's session, terminating the application, or sending an alert to organizational personnel). Runtime application self-protection solutions can be deployed in either a monitor or protection mode.
Assessment Objective
{{ insert: param, si-07.17_odp }} are implemented for application self-protection at runtime.
System and information integrity policy
system and information integrity procedures
procedures addressing software and information integrity
system design documentation
system configuration settings and associated documentation
list of known vulnerabilities addressed by runtime instrumentation
system security plan
other relevant documents or records
Organizational personnel responsible for software, firmware, and/or information integrity
organizational personnel with information security responsibilities
system/network administrators
system developer
Software, firmware, and information integrity verification tools
mechanisms supporting and/or implementing runtime application self-protection