Knowledge is Power

Sitewide Search

Search Bare Metal Cyber

Search courses, individual lessons, wiki entries, books, podcasts, magazine articles, Daily Cyber News, and Darwin.

NIST SP 800-171 CUI Protection Center

03.14 — System and Information Integrity

Study this CUI requirement family as a connected set of implementation decisions, evidence expectations, and assessment procedures.

5Active requirements
3Withdrawn records
3Parameters
24Assessment objectives

CUI requirement family

System and Information Integrity

Use this family as a planning boundary, but assess every applicable requirement against the real CUI system boundary, inherited services, organization-defined parameters, and operational evidence.

5 active3 withdrawnRevision 3
SI

Family catalog

Requirements and assessment procedures.

Withdrawn records remain available and link to the requirements where their intent was incorporated or addressed.

03.14.01Active

Flaw Remediation

Organizations identify systems that are affected by announced software and firmware flaws, including potential vulnerabilities that result from those flaws, and report this information to designated personnel with information security responsibilities. Security-relevant updates include patches, service packs, hot fixes, and anti-virus signatures. Organizations address the flaws discovered during security assessments,

03.14.02Active

Malicious Code Protection

Malicious code insertions occur through the exploitation of system vulnerabilities. Malicious code can be inserted into the system in a variety of ways, including email, the internet, and portable storage devices. Malicious code includes viruses, worms, Trojan horses, and spyware. Malicious code can be encoded in various formats, contained in compressed or hidden files, or hidden in files using techniques such as ste

03.14.03Active

Security Alerts, Advisories, and Directives

There are many publicly available sources of system security alerts and advisories. The Department of Homeland Security’s Cybersecurity and Infrastructure Security Agency (CISA), the National Security Agency (NSA), and the Federal Bureau of Investigation (FBI) generate security alerts and advisories to maintain situational awareness across the Federal Government and in nonfederal organizations. Software vendors, subs

03.14.04Withdrawn

Withdrawn requirement

Withdrawn NIST SP 800-171 Rev. 3 requirement 03.14.04; use the recorded replacement relationships.

03.14.05Withdrawn

Withdrawn requirement

Withdrawn NIST SP 800-171 Rev. 3 requirement 03.14.05; use the recorded replacement relationships.

03.14.06Active

System Monitoring

System monitoring involves external and internal monitoring. Internal monitoring includes the observation of events that occur within the system. External monitoring includes the observation of events that occur at the system boundary. Organizations can monitor the system by observing audit record activities in real time or by observing other system aspects, such as access patterns, characteristics of access, and oth

03.14.07Withdrawn

Withdrawn requirement

Withdrawn NIST SP 800-171 Rev. 3 requirement 03.14.07; use the recorded replacement relationships.

03.14.08Active

Information Management and Retention

Federal agencies consider data retention requirements for nonfederal organizations. Retaining CUI on nonfederal systems after contracts or agreements have concluded increases the attack surface for those systems and the risk of the information being compromised. NARA provides federal policy and guidance on records retention and schedules.