id: "SI-14(01)" title: "Refresh from Trusted Sources" family: "SI" family_name: "System and Information Integrity" sort_id: "si-14.01" priority: "P1" implementation_level: "organization" parent: "SI-14" enhancement: True


Statement

Obtain software and data employed during system component and service refreshes from the following trusted sources: {{ insert: param, si-14.01_odp }}.

Guidance

Trusted sources include software and data from write-once, read-only media or from selected offline secure storage facilities.

Assessment Objective

the software and data employed during system component and service refreshes are obtained from {{ insert: param, si-14.01_odp }}.

System and information integrity policy

system and information integrity procedures

procedures addressing non-persistence for system components

system design documentation

system configuration settings and associated documentation

system audit records

system security plan

other relevant documents or records

Organizational personnel responsible for obtaining component and service refreshes from trusted sources

organizational personnel with information security responsibilities

Organizational processes for defining and obtaining component and service refreshes from trusted sources

automated mechanisms supporting and/or implementing component and service refreshes