id: "SI-16" title: "Memory Protection" family: "SI" family_name: "System and Information Integrity" sort_id: "si-16" priority: "P1" implementation_level: "system"


Statement

Implement the following controls to protect the system memory from unauthorized code execution: {{ insert: param, si-16_odp }}.

Guidance

Some adversaries launch attacks with the intent of executing code in non-executable regions of memory or in memory locations that are prohibited. Controls employed to protect memory include data execution prevention and address space layout randomization. Data execution prevention controls can either be hardware-enforced or software-enforced with hardware enforcement providing the greater strength of mechanism.

Assessment Objective

{{ insert: param, si-16_odp }} are implemented to protect the system memory from unauthorized code execution.

System and information integrity policy

system and information integrity procedures

procedures addressing memory protection for the system

system design documentation

system configuration settings and associated documentation

list of security safeguards protecting system memory from unauthorized code execution

system audit records

system security plan

other relevant documents or records

Organizational personnel responsible for memory protection

organizational personnel with information security responsibilities

system/network administrators

system developer

Automated mechanisms supporting and/or implementing safeguards to protect the system memory from unauthorized code execution