id: "SI-21" title: "Information Refresh" family: "SI" family_name: "System and Information Integrity" sort_id: "si-21" priority: "P1" implementation_level: "system"


Statement

Refresh {{ insert: param, si-21_odp.01 }} at {{ insert: param, si-21_odp.02 }} or generate the information on demand and delete the information when no longer needed.

Guidance

Retaining information for longer than it is needed makes it an increasingly valuable and enticing target for adversaries. Keeping information available for the minimum period of time needed to support organizational missions or business functions reduces the opportunity for adversaries to compromise, capture, and exfiltrate that information.

Assessment Objective

the {{ insert: param, si-21_odp.01 }} is refreshed {{ insert: param, si-21_odp.02 }} or is generated on demand and deleted when no longer needed.

System and information integrity policy

system and information integrity procedures

personally identifiable information processing policy

procedures addressing software and information integrity

system design documentation

system configuration settings and associated documentation

information refresh procedures

list of information to be refreshed

system security plan

privacy plan

other relevant documents or records

Organizational personnel responsible for refreshing information

organizational personnel with information security and privacy responsibilities

organizational personnel with systems security engineering responsibilities

system developers

Mechanisms for information refresh

organizational processes for information refresh