id: "SI-10(05)" title: "Restrict Inputs to Trusted Sources and Approved Formats" family: "SI" family_name: "System and Information Integrity" sort_id: "si-10.05" priority: "P1" implementation_level: "system" parent: "SI-10" enhancement: True
Statement
Restrict the use of information inputs to {{ insert: param, si-10.05_odp.01 }} and/or {{ insert: param, si-10.05_odp.02 }}.
Guidance
Restricting the use of inputs to trusted sources and in trusted formats applies the concept of authorized or permitted software to information inputs. Specifying known trusted sources for information inputs and acceptable formats for such inputs can reduce the probability of malicious activity. The information inputs are those defined by the organization in the base control ( SI-10).
Assessment Objective
the use of information inputs is restricted to {{ insert: param, si-10.05_odp.01 }} and/or {{ insert: param, si-10.05_odp.02 }}.
System and information integrity policy
system and information integrity procedures
procedures addressing information input validation
system design documentation
system configuration settings and associated documentation
list of trusted sources for information inputs
list of acceptable formats for input restrictions
system audit records
system security plan
other relevant documents or records
Organizational personnel responsible for information input validation
organizational personnel with information security responsibilities
system/network administrators
system developer
Organizational processes for restricting information inputs
automated mechanisms supporting and/or implementing restriction of information inputs