# SI-07 Software, Firmware, and Information Integrity

NIST SP 800-53 control. Family: SI System and Information Integrity. Function: detective. Baselines: moderate, high. Mapping licence: CC BY-SA 4.0.

Statement: a. Employ integrity verification tools to detect unauthorized changes to the following software, firmware, and information: [Assignment: organization-defined software, firmware, and information]; and b. Take the following actions when unauthorized changes to the software, firmware, and information are detected: [Assignment: organization-defined actions].
Guidance: Unauthorized changes to software, firmware, and information can occur due to errors or malicious activity. Software includes operating systems (with key internal components, such as kernels or drivers), middleware, and applications. Firmware interfaces include Unified Extensible Firmware Interface (UEFI) and Basic Input/Output System (BIOS). Information includes personally identifiable information and metadata that contains security and privacy attributes associated with information. Integrity-checking mechanisms—including parity checks, cyclical redundancy checks, cryptographic hashes, and associated tools—can automatically monitor the integrity of systems and hosted applications.

## Enhancements (13)
- SI-07(01) Integrity Checks. Baselines: moderate, high
- SI-07(02) Automated Notifications of Integrity Violations. Baselines: high
- SI-07(03) Centrally Managed Integrity Tools
- SI-07(05) Automated Response to Integrity Violations. Baselines: high
- SI-07(06) Cryptographic Protection
- SI-07(07) Integration of Detection and Response. Baselines: moderate, high
- SI-07(08) Auditing Capability for Significant Events
- SI-07(09) Verify Boot Process
- SI-07(10) Protection of Boot Firmware
- SI-07(12) Integrity Verification
- SI-07(15) Code Authentication. Baselines: high
- SI-07(16) Time Limit on Process Execution Without Supervision
- SI-07(17) Runtime Application Self-protection
Withdrawn by NIST: SI-07(04) (now in SR-09); SI-07(11) (now in CM-07(06)); SI-07(13) (now in CM-07(07)); SI-07(14) (now in CM-07(08)).
Each enhancement's statement: /api/v1/controls/SI-07?fields=enhancements

## Patterns that use it (17)
- Critical (5): SP-028 Secure DevOps Pipeline Pattern; SP-034 Cyber Resilience; SP-039 Client-Side Encryption and Data Privacy; SP-040 Post-Quantum Cryptography and Quantum Readiness; SP-050 Mobile Security Architecture (draft)
- Important (11): SP-001 Client Module; SP-002 Server Module; SP-016 DMZ Module; SP-023 Industrial Control Systems; SP-025 Advanced Monitoring and Detection; SP-026 PCI Full Environment; SP-029 Zero Trust Architecture; SP-031 Security Monitoring and Response; SP-033 Passkey Authentication; SP-036 Incident Response; SP-052 Decentralised Identity & Verifiable Credentials (draft)
- Standard (1): SP-053 Zero-Knowledge Proof Architecture (draft)

## Clauses by framework (68 frameworks)
- pci_dss_v4: 11.5, 11.6
- nist_csf_2: DE.CM-09, ID.RA-09, PR.DS-01, PR.DS-02, PR.DS-10, PR.PS-02, RC.RP-03, RC.RP-05. OSA's own, not in NIST's crosswalk: RC.RP-03, RC.RP-05
- cis_controls_v8: CIS 13.2, CIS 13.7
- soc2_tsc: CC6.6, CC6.6-POF2, CC6.8
- iso_42001_2023: A.6.2.4, A.6.2.6
- iec_62443: 3-3 SR 3.1, 3-3 SR 3.4
- asd_e8: E8-3 ML3
- apra_cps_234: Para 22-23
- anssi: Hygiene.20, Hygiene.34, SecNumCloud.13.6
- osfi_b13: B-13.3.2, B-13.3.3
- finma_circular: IV.B.d(59), IV.C(64), IV.D(78)
- gdpr: Art.5(1)(d), Art.5(1)(f), Art.32(1)(b)
- dora: Art.9(4)(b), Art.9(4)(e)
- rbi_csf: Annex1.5, Annex1.13
- fisc: FISC.T7, FISC.T12, FISC.T14
- lgpd_bcb: BCB.Art.3, LGPD.Art.46
- hkma_tme1: TME1.4.3, TME1.7.3, TME1.10.2
- mlps_2: 8.1.2.3, 8.1.3.6, 8.1.4.4, 8.1.4.6, 8.1.4.7
- cra: CRA.I.2b, CRA.I.2c, CRA.I.2f, CRA.II.7
- swift_cscf: SWIFT.6.2, SWIFT.6.3
- cbuae: CR-7
- nca_ecc: 2-3, 5-1
- qatar_nia: OS
- sama_csf: 3.3
- uae_ia: T7
- bog_cisd: CISD-VI
- bom_ctrm: 3.6
- cbe_csf: CTO-7
- cbn_csf: Part3.3
- popia: s16, s19
- sa_js2: JS2-7.2, JS2-8.4, JS2-8.5
- bcbs_239: Principle 3, Principle 7
- bot_cyber: Ch2.6, Ch9.1
- cpmi_pfmi: CG.DE, CG.PR, PFMI.P17
- eba_ict: 3.4.4
- ecb_croe: CROE.2.3.3, CROE.2.4
- ffiec_is: II.C.12, III.B
- hipaa_sr: §164.312(c)(1), §164.312(c)(2), §164.312(e)(2)(i)
- iosco_cyber: PROT-3, PROT-6, RR-3, TEST-5
- nydfs_500: 500.8
- sebi_cscrf: PR.ES, PR.IP
- cmmc_2: SI
- nrc_73_54: RG5.71-A-SI
- ieee_1686: 5.3
- api_1164: Sec 7
- iaea_nss: Sec 5.4
- pci_pts: B, F, L
- fips_140: FIPS 140-3 §7.5, FIPS 140-3 §7.10
- pci_hsm: 8
- common_criteria: CC Part 2 — FPT
- isae_3402: Clause 4
- fca_sysc_13: SYSC 13.7.1, SYSC 13.7.4
- fda_21_cfr_11: §11.10(b), §11.10(f), §11.70
- fda_cyber: SA-3, ST-1
- hitrust_csf: 09.c, 11.c
- lloyds_ms: MS8.4, MS8.10
- naic_ds: 4B, 5
- pra_ss1_23: P3.2, P4.3
- solvency_ii: EIOPA-ICT-4.8, Pillar3-Reporting
- owasp_masvs_v2: MASVS-RESILIENCE-1, MASVS-RESILIENCE-2, MASVS-RESILIENCE-3, MASVS-RESILIENCE-4
- csa_ccm_v4: CCC-04, CCC-07
- csa_aicm: AIS-09, AIS-13, AIS-14, CCC-04, CCC-07, MDS-06, MDS-08
- ccss_v9: 1.01.3, 1.02.4
- mica: Art.88(1)
- basel_sco60: SCO60.11, SCO60.14, SCO60.21, SCO60.23, SCO60.51, SCO60.52, SCO60.65, SCO60.71
- bssc: NOS-02, TIS-05
- sec_custody_digital: SEC-CD-09, SEC-CD-13
- dpdpa: Act.8(5), Rules.Sch1.B.7
OSA's mapping for nist_csf_2 takes NIST's published crosswalk as its base. A clause not marked as OSA's own is in that crosswalk.

## More
- This control as JSON, with guidance and ATT&CK techniques: /api/v1/controls/SI-07
- Clauses only: /api/v1/controls/SI-07?fields=mappings
- Page for people: /controls/si-07/
