id: "SI-14(01)" title: "Refresh from Trusted Sources" family: "SI" family_name: "System and Information Integrity" sort_id: "si-14.01" priority: "P1" implementation_level: "organization" parent: "SI-14" enhancement: True
Statement
Obtain software and data employed during system component and service refreshes from the following trusted sources: {{ insert: param, si-14.01_odp }}.
Guidance
Trusted sources include software and data from write-once, read-only media or from selected offline secure storage facilities.
Assessment Objective
the software and data employed during system component and service refreshes are obtained from {{ insert: param, si-14.01_odp }}.
System and information integrity policy
system and information integrity procedures
procedures addressing non-persistence for system components
system design documentation
system configuration settings and associated documentation
system audit records
system security plan
other relevant documents or records
Organizational personnel responsible for obtaining component and service refreshes from trusted sources
organizational personnel with information security responsibilities
Organizational processes for defining and obtaining component and service refreshes from trusted sources
automated mechanisms supporting and/or implementing component and service refreshes