← Controls / SI

SI-08 Spam Protection

System and Information Integrity

Moderate High

Description

a. Employ spam protection mechanisms at system entry and exit points to detect and act on unsolicited messages; and b. Update spam protection mechanisms when new releases are available in accordance with organizational configuration management policy and procedures.

Supplemental Guidance

System entry and exit points include firewalls, remote-access servers, electronic mail servers, web servers, proxy servers, workstations, notebook computers, and mobile devices. Spam can be transported by different means, including email, email attachments, and web accesses. Spam protection mechanisms include signature definitions.

Enhancements (2)

What NIST adds to this control. Select one to read its statement.

SI-08(02) Automatic Updates ModerateHigh

Automatically update spam protection mechanisms [Assignment: organization-defined frequency].

SI-08(03) Continuous Learning Capability

Implement spam protection mechanisms with a learning capability to more effectively identify legitimate communications traffic.

Withdrawn by NIST:

  • SI-08(01) Central Management, now in PL-09

Patterns that use this control (1)

Grouped by the emphasis each pattern gives it.

Standard (1)

Compliance Mappings

ISO 27001:2022

A.8.7

ISO 27002:2022

8.7

CIS Controls v8

CIS 9CIS 9.5CIS 9.7CIS 10

PCI DSS v4.0.1

5.4

BSI IT-Grundschutz

OPS.1.1.4

ANSSI

Hygiene.21Hygiene.22SecNumCloud.13.1

FINMA Circular 2023/1

IV.B.d(59)IV.C(64)

OSFI B-13

B-13.3.2B-13.3.3

EU GDPR

Art.32(1)(b)

EU DORA

Art.9(4)(b)

BIO2

8.7

RBI CSF

Annex1.10Annex1.14

MLPS 2.0

8.1.3.4

DNB Good Practice

DNB.19.1

NCA ECC

2-4

Qatar NIA

CS

CBE CSF

CTO-8

SA JS2

JS2-8.4

IOSCO Cyber Resilience

DET-3

FFIEC IS

II.C.12

HIPAA Security Rule

§164.308(a)(5)(ii)(B)

SEBI CSCRF

EMAIL-SEC

CMMC 2.0

SI

Lloyd's Minimum Standards

MS8.10

HITRUST CSF v11

09.c

ISO 27799

12.2

NHS DSPT

NDG-9.3NDG-9.4

ISO 17799 (legacy)

None.

COBIT 4.1 (legacy)

DS5.9