← Controls / SI

SI-06 Security and Privacy Function Verification

System and Information Integrity

High

Description

a. Verify the correct operation of [Assignment: organization-defined security and privacy functions]; b. Perform the verification of the functions specified in SI-06a [Selection (one or more): [Assignment: organization-defined system transitional states]; upon command by user with appropriate privilege; [Assignment: organization-defined frequency]]; c. Alert [Assignment: organization-defined personnel or roles] to failed security and privacy verification tests; and d. [Selection (one or more): Shut the system down; Restart the system; [Assignment: organization-defined alternative action(s)]] when anomalies are discovered.

Supplemental Guidance

Transitional states for systems include system startup, restart, shutdown, and abort. System notifications include hardware indicator lights, electronic alerts to system administrators, and messages to local computer consoles. In contrast to security function verification, privacy function verification ensures that privacy functions operate as expected and are approved by the senior agency official for privacy or that privacy attributes are applied or used as expected.

Changes from Rev 4

Title changed from 'Security Function Verification' Control text changes 'Notifies' to 'Alert' Parameter adds 'and privacy' Discussion expanded to include privacy function verification

Enhancements (2)

What NIST adds to this control. Select one to read its statement.

SI-06(02) Automation Support for Distributed Testing

Implement automated mechanisms to support the management of distributed security and privacy function testing.

SI-06(03) Report Verification Results

Report the results of security and privacy function verification to [Assignment: organization-defined personnel or roles].

Withdrawn by NIST:

  • SI-06(01) Notification of Failed Security Tests, now in SI-06

Compliance Mappings

ISO 42001:2023

A.6.2.4

ANSSI

Hygiene.31SecNumCloud.13.6

FINMA Circular 2023/1

IV.D(75)IV.D(76)

OSFI B-13

B-13.3.3B-13.3.5

EU GDPR

Art.5(1)(d)Art.32(1)(d)

EU DORA

Art.10(1)Art.10(2)

RBI CSF

Annex1.16

EU CRA

CRA.II.3

POPIA

s16

IOSCO Cyber Resilience

DET-2DET-4TEST-3

BCBS 239

Principle 3Principle 7

CPMI-IOSCO PFMI

CG.TE

ECB CROE

CROE.2.6.1

EBA ICT Guidelines

3.4.6

BOT Cyber Resilience

Ch10.1

CMMC 2.0

SI

FIPS 140-3

FIPS 140-3 §7.10

Common Criteria

CC Part 2 — FPT

PRA SS1/23

P3.2P4.3P5.2

FCA SYSC 13

SYSC 13.7.1SYSC 13.7.5

HITRUST CSF v11

10.d

FDA 21 CFR Part 11

§11.10(a)§11.300(e)

FDA Cybersecurity Guidance

SA-5

OWASP MASVS v2.1

MASVS-RESILIENCE-1

Basel SCO60

SCO60.14SCO60.21SCO60.52

SEC Custody (Digital Assets)

SEC-CD-13

India DPDPA

Rules.6(1)(g)

ISO 17799 (legacy)

None.

COBIT 4.1 (legacy)

None.