id: "SI-23" title: "Information Fragmentation" family: "SI" family_name: "System and Information Integrity" sort_id: "si-23" priority: "P1" implementation_level: "system"
Statement
Based on {{ insert: param, si-23_odp.01 }}:
Fragment the following information: {{ insert: param, si-23_odp.02 }} ; and
Distribute the fragmented information across the following systems or system components: {{ insert: param, si-23_odp.03 }}.
Guidance
One objective of the advanced persistent threat is to exfiltrate valuable information. Once exfiltrated, there is generally no way for the organization to recover the lost information. Therefore, organizations may consider dividing the information into disparate elements and distributing those elements across multiple systems or system components and locations. Such actions will increase the adversary’s work factor to capture and exfiltrate the desired information and, in so doing, increase the probability of detection. The fragmentation of information impacts the organization’s ability to access the information in a timely manner. The extent of the fragmentation is dictated by the impact or classification level (and value) of the information, threat intelligence information received, and whether data tainting is used (i.e., data tainting-derived information about the exfiltration of some information could result in the fragmentation of the remaining information).
Assessment Objective: under {{ insert: param, si-23_odp.01 }}, {{ insert: param, si-23_odp.02 }} is fragmented;
Assessment Objective: under {{ insert: param, si-23_odp.01 }} , the fragmented information is distributed across {{ insert: param, si-23_odp.03 }}.
System and information integrity policy
system and information integrity procedures
personally identifiable information processing policy
procedures addressing software and information integrity
system design documentation
system configuration settings and associated documentation
procedures to identify information for fragmentation and distribution across systems/system components
list of distributed and fragmented information
list of circumstances requiring information fragmentation
enterprise architecture
system security architecture
system security plan
privacy plan
other relevant documents or records
Organizational personnel with information security and privacy responsibilities
organizational personnel with systems security engineering responsibilities
system developers
security architects
Organizational processes to identify information for fragmentation and distribution across systems/system components
automated mechanisms supporting and/or implementing information fragmentation and distribution across systems/system components