SI-07 Software, Firmware, and Information Integrity
System and Information Integrity
Description
a. Employ integrity verification tools to detect unauthorized changes to the following software, firmware, and information: [Assignment: organization-defined software, firmware, and information]; and b. Take the following actions when unauthorized changes to the software, firmware, and information are detected: [Assignment: organization-defined actions].
Supplemental Guidance
Unauthorized changes to software, firmware, and information can occur due to errors or malicious activity. Software includes operating systems (with key internal components, such as kernels or drivers), middleware, and applications. Firmware interfaces include Unified Extensible Firmware Interface (UEFI) and Basic Input/Output System (BIOS). Information includes personally identifiable information and metadata that contains security and privacy attributes associated with information. Integrity-checking mechanisms—including parity checks, cyclical redundancy checks, cryptographic hashes, and associated tools—can automatically monitor the integrity of systems and hosted applications.
Changes from Rev 4
Control text adds requirement to take actions when unauthorized changes are detected Parameter added for specifying organization-defined actions Discussion includes additional examples
Enhancements (13)
What NIST adds to this control. Select one to read its statement.
SI-07(01) Integrity Checks ModerateHigh
Perform an integrity check of [Assignment: organization-defined software, firmware, and information] [Selection (one or more): at startup; at [Assignment: organization-defined transitional states or security-relevant events]; [Assignment: organization-defined frequency]].
SI-07(02) Automated Notifications of Integrity Violations High
Employ automated tools that provide notification to [Assignment: organization-defined personnel or roles] upon discovering discrepancies during integrity verification.
SI-07(03) Centrally Managed Integrity Tools
Employ centrally managed integrity verification tools.
SI-07(05) Automated Response to Integrity Violations High
Automatically [Selection (one or more): shut the system down; restart the system; implement [Assignment: organization-defined controls]] when integrity violations are discovered.
SI-07(06) Cryptographic Protection
Implement cryptographic mechanisms to detect unauthorized changes to software, firmware, and information.
SI-07(07) Integration of Detection and Response ModerateHigh
Incorporate the detection of the following unauthorized changes into the organizational incident response capability: [Assignment: organization-defined security-relevant changes to the system].
SI-07(08) Auditing Capability for Significant Events
Upon detection of a potential integrity violation, provide the capability to audit the event and initiate the following actions: [Selection (one or more): generate an audit record; alert current user; alert [Assignment: organization-defined personnel or roles]; [Assignment: organization-defined other actions]].
SI-07(09) Verify Boot Process
Verify the integrity of the boot process of the following system components: [Assignment: organization-defined system components].
SI-07(10) Protection of Boot Firmware
Implement the following mechanisms to protect the integrity of boot firmware in [Assignment: organization-defined system components]: [Assignment: organization-defined mechanisms].
SI-07(12) Integrity Verification
Require that the integrity of the following software be verified prior to execution: [Assignment: organization-defined software].
SI-07(15) Code Authentication High
Implement cryptographic mechanisms to authenticate the following software or firmware components prior to installation: [Assignment: organization-defined software or firmware components].
SI-07(16) Time Limit on Process Execution Without Supervision
Prohibit processes from executing without supervision for more than [Assignment: organization-defined time period].
SI-07(17) Runtime Application Self-protection
Implement [Assignment: organization-defined controls] for application self-protection at runtime.
Patterns that use this control (17)
Grouped by the emphasis each pattern gives it.
Critical (5)
Important (11)
- SP-001 Client Module
- SP-002 Server Module
- SP-016 DMZ Module
- SP-023 Industrial Control Systems
- SP-025 Advanced Monitoring and Detection
- SP-026 PCI Full Environment
- SP-029 Zero Trust Architecture
- SP-031 Security Monitoring and Response
- SP-033 Passkey Authentication
- SP-036 Incident Response
- SP-052 Decentralised Identity & Verifiable Credentials (draft)
Standard (1)
MITRE ATT&CK Techniques (209)
ATT&CK v16.1Techniques mitigated by this control, mapped via CTID.