SI-08 Spam Protection
System and Information Integrity
Description
a. Employ spam protection mechanisms at system entry and exit points to detect and act on unsolicited messages; and b. Update spam protection mechanisms when new releases are available in accordance with organizational configuration management policy and procedures.
Supplemental Guidance
System entry and exit points include firewalls, remote-access servers, electronic mail servers, web servers, proxy servers, workstations, notebook computers, and mobile devices. Spam can be transported by different means, including email, email attachments, and web accesses. Spam protection mechanisms include signature definitions.
Enhancements (2)
What NIST adds to this control. Select one to read its statement.
SI-08(02) Automatic Updates ModerateHigh
Automatically update spam protection mechanisms [Assignment: organization-defined frequency].
SI-08(03) Continuous Learning Capability
Implement spam protection mechanisms with a learning capability to more effectively identify legitimate communications traffic.
Withdrawn by NIST:
- SI-08(01) Central Management, now in PL-09
Patterns that use this control (1)
Grouped by the emphasis each pattern gives it.
Standard (1)
MITRE ATT&CK Techniques (20)
ATT&CK v16.1Techniques mitigated by this control, mapped via CTID.