{"data":{"id":"SI-06","name":"Security and Privacy Function Verification","family":"SI","family_name":"System and Information Integrity","withdrawn":false,"description":"a. Verify the correct operation of [Assignment: organization-defined security and privacy functions];\nb. Perform the verification of the functions specified in SI-06a [Selection (one or more): [Assignment: organization-defined system transitional states]; upon command by user with appropriate privilege; [Assignment: organization-defined frequency]];\nc. Alert [Assignment: organization-defined personnel or roles] to failed security and privacy verification tests; and\nd. [Selection (one or more): Shut the system down; Restart the system; [Assignment: organization-defined alternative action(s)]] when anomalies are discovered.","supplemental_guidance":"Transitional states for systems include system startup, restart, shutdown, and abort. System notifications include hardware indicator lights, electronic alerts to system administrators, and messages to local computer consoles. In contrast to security function verification, privacy function verification ensures that privacy functions operate as expected and are approved by the senior agency official for privacy or that privacy attributes are applied or used as expected.","enhancements":[{"id":"SI-06(01)","name":"Notification of Failed Security Tests","withdrawn":true,"incorporated_into":["SI-06"]},{"id":"SI-06(02)","name":"Automation Support for Distributed Testing","statement":"Implement automated mechanisms to support the management of distributed security and privacy function testing.","baselines":[]},{"id":"SI-06(03)","name":"Report Verification Results","statement":"Report the results of security and privacy function verification to [Assignment: organization-defined personnel or roles].","baselines":[]}],"baseline_low":false,"baseline_moderate":false,"baseline_high":true,"nist_800_53":{"rev5":{"id":"SI-06","name":"Security and Privacy Function Verification","description":"a. Verify the correct operation of [Assignment: organization-defined security and privacy functions];\nb. Perform the verification of the functions specified in SI-06a [Selection (one or more): [Assignment: organization-defined system transitional states]; upon command by user with appropriate privilege; [Assignment: organization-defined frequency]];\nc. Alert [Assignment: organization-defined personnel or roles] to failed security and privacy verification tests; and\nd. [Selection (one or more): Shut the system down; Restart the system; [Assignment: organization-defined alternative action(s)]] when anomalies are discovered.","discussion":"Transitional states for systems include system startup, restart, shutdown, and abort. System notifications include hardware indicator lights, electronic alerts to system administrators, and messages to local computer consoles. In contrast to security function verification, privacy function verification ensures that privacy functions operate as expected and are approved by the senior agency official for privacy or that privacy attributes are applied or used as expected.","related_controls":["CA-07","CM-04","CM-06","SI-07"],"baseline_low":false,"baseline_moderate":false,"baseline_high":true,"baseline_privacy":false,"new_in_rev5":false,"changes_from_rev4":"Title changed from 'Security Function Verification' Control text changes 'Notifies' to 'Alert' Parameter adds 'and privacy' Discussion expanded to include privacy function verification"}},"compliance_mappings":{"iso_27001_2022":[],"iso_27002_2022":[],"cobit_2019":[],"pci_dss_v4":[],"nist_csf_2":[],"cis_controls_v8":[],"soc2_tsc":[],"finos_ccc":[],"iso_42001_2023":["A.6.2.4"],"iec_62443":[],"asd_e8":[],"nis2":[],"apra_cps_234":[],"mas_trm":[],"pra_op_resilience":[],"bsi_grundschutz":[],"anssi":["Hygiene.31","SecNumCloud.13.6"],"osfi_b13":["B-13.3.3","B-13.3.5"],"finma_circular":["IV.D(75)","IV.D(76)"],"gdpr":["Art.5(1)(d)","Art.32(1)(d)"],"dora":["Art.10(1)","Art.10(2)"],"bio2":[],"rbi_csf":["Annex1.16"],"fisc":[],"lgpd_bcb":[],"hkma_tme1":[],"mlps_2":[],"dnb_good_practice":[],"cra":["CRA.II.3"],"swift_cscf":[],"popia":["s16"],"bcbs_239":["Principle 3","Principle 7"],"bot_cyber":["Ch10.1"],"cpmi_pfmi":["CG.TE"],"eba_ict":["3.4.6"],"ecb_croe":["CROE.2.6.1"],"iosco_cyber":["DET-2","DET-4","TEST-3"],"cmmc_2":["SI"],"nerc_cip":[],"nrc_73_54":[],"tsa_psd":[],"ieee_1686":[],"ferc_cip":[],"doe_c2m2":[],"api_1164":[],"awia":[],"iaea_nss":[],"pci_pts":[],"fips_140":["FIPS 140-3 §7.10"],"cbest":[],"tiber_eu":[],"pci_hsm":[],"common_criteria":["CC Part 2 — FPT"],"isae_3402":[],"fca_sysc_13":["SYSC 13.7.1","SYSC 13.7.5"],"fda_21_cfr_11":["§11.10(a)","§11.300(e)"],"fda_cyber":["SA-5"],"hitrust_csf":["10.d"],"iso_27799":[],"lloyds_ms":[],"naic_ds":[],"nhs_dspt":[],"pra_ss1_23":["P3.2","P4.3","P5.2"],"solvency_ii":[],"owasp_masvs_v2":["MASVS-RESILIENCE-1"],"csa_ccm_v4":[],"csa_aicm":[],"ccss_v9":[],"mica":[],"basel_sco60":["SCO60.14","SCO60.21","SCO60.52"],"bssc":[],"sec_custody_digital":["SEC-CD-13"],"dpdpa":["Rules.6(1)(g)"]},"attack_techniques":[],"metadata":{"last_reviewed":"2026-10-03","review_notes":"2026-10-03: baselines LMH to --H, from NIST SP 800-53B Release 5.2.0.","mapping_status":"complete"},"function":"detective","used_by_patterns":["SP-001","SP-002","SP-012","SP-016","SP-025","SP-026","SP-050"]}}