# SI-09 Information Input Restrictions

NIST SP 800-53 control. Family: SI System and Information Integrity. Function: detective. In no baseline. Mapping licence: CC BY-SA 4.0.
Withdrawn from SP 800-53 by NIST. Its content moved into AC-02, AC-03, AC-05, AC-06.

Statement: The organization restricts the capability to input information to the information system to authorized personnel.
Guidance: Restrictions on personnel authorized to input information to the information system may extend beyond the typical access controls employed by the system and include limitations based on specific operational/project responsibilities.

## Patterns that use it (2)
- Standard (2): SP-013 Data Security Pattern; SP-026 PCI Full Environment

## Clauses by framework (5 frameworks)
- iso_42001_2023: A.7.4
- anssi: Hygiene.14, SecNumCloud.10.3
- osfi_b13: B-13.3.2
- finma_circular: IV.D(78), IV.D(80)
- gdpr: Art.5(1)(f), Art.25(2)

## More
- This control as JSON, with guidance and ATT&CK techniques: /api/v1/controls/SI-09
- Clauses only: /api/v1/controls/SI-09?fields=mappings
- Page for people: /controls/si-09/
