id: "SI-21" title: "Information Refresh" family: "SI" family_name: "System and Information Integrity" sort_id: "si-21" priority: "P1" implementation_level: "system"
Statement
Refresh {{ insert: param, si-21_odp.01 }} at {{ insert: param, si-21_odp.02 }} or generate the information on demand and delete the information when no longer needed.
Guidance
Retaining information for longer than it is needed makes it an increasingly valuable and enticing target for adversaries. Keeping information available for the minimum period of time needed to support organizational missions or business functions reduces the opportunity for adversaries to compromise, capture, and exfiltrate that information.
Assessment Objective
the {{ insert: param, si-21_odp.01 }} is refreshed {{ insert: param, si-21_odp.02 }} or is generated on demand and deleted when no longer needed.
System and information integrity policy
system and information integrity procedures
personally identifiable information processing policy
procedures addressing software and information integrity
system design documentation
system configuration settings and associated documentation
information refresh procedures
list of information to be refreshed
system security plan
privacy plan
other relevant documents or records
Organizational personnel responsible for refreshing information
organizational personnel with information security and privacy responsibilities
organizational personnel with systems security engineering responsibilities
system developers
Mechanisms for information refresh
organizational processes for information refresh