Knowledge is Power

Sitewide Search

Search Bare Metal Cyber

Search courses, individual lessons, wiki entries, books, podcasts, magazine articles, Daily Cyber News, and Darwin.

NIST SP 800-172 Enhanced CUI Protection Center

03.14 — System and Information Integrity

Study this CUI requirement family as a connected set of implementation decisions, evidence expectations, and assessment procedures.

15Active requirements
4Withdrawn records
43Parameters
30Assessment objectives

CUI requirement family

System and Information Integrity

Use this family as a planning boundary, but assess every applicable requirement against the real CUI system boundary, inherited services, organization-defined parameters, and operational evidence.

15 active4 withdrawnRevision 3
SI

Family catalog

Requirements and assessment procedures.

Withdrawn records remain available and link to the requirements where their intent was incorporated or addressed.

03.14.01EActive

Software, Firmware, and Information Integrity

Verifying the integrity of security-critical or essential software is an important capability since corrupted software is the primary attack vector used by adversaries to undermine or disrupt the proper functioning of systems. Unauthorized changes to software, firmware, and information can occur due to errors or malicious activity. Software includes boot firmware, operating systems with key internal components (e.g.,

03.14.02EWithdrawn

Withdrawn requirement

Withdrawn NIST SP 800-172 Rev. 3 requirement 03.14.02E; use the recorded replacement relationships.

03.14.03EWithdrawn

Withdrawn requirement

Withdrawn NIST SP 800-172 Rev. 3 requirement 03.14.03E; use the recorded replacement relationships.

03.14.04EActive

Refresh From Trusted Sources

Trusted sources include software and data from write-once, read-only media or from selected offline secure storage facilities. This requirement does not enhance a specific requirement in SP 800-171 but can be used to strengthen the protection of CUI associated with critical programs or high value assets.

03.14.05EActive

Non-Persistent Information

Retaining information longer than is required makes that information a potential target for advanced adversaries searching for high value assets to compromise through unauthorized disclosure, unauthorized modification, or exfiltration. For system-related information, unnecessary retention provides adversaries with information that can assist in their reconnaissance and lateral movement through the system. This requir

03.14.06EWithdrawn

Withdrawn requirement

Withdrawn NIST SP 800-172 Rev. 3 requirement 03.14.06E; use the recorded replacement relationships.

03.14.07EWithdrawn

Withdrawn requirement

Withdrawn NIST SP 800-172 Rev. 3 requirement 03.14.07E; use the recorded replacement relationships.

03.14.08EActive

Integrity Checks

Security-relevant events include the identification of new threats to which organizational systems are susceptible and the installation of hardware, software, or firmware. Transitional states include system startup, restart, shutdown, and abort. This requirement is sourced to a control tailored out of the SP 800-53B .13 moderate baseline in SP 800-171.

03.14.09EActive

Cryptographic Protection

Cryptographic mechanisms used to protect integrity include digital signatures and the computation and application of signed hashes using asymmetric cryptography, protecting the confidentiality of the key used to generate the hash, and using the public key to verify the hash information. Organizations that use cryptographic mechanisms also consider cryptographic key management solutions. This requirement does not enha

03.14.10EActive

Protection of Boot Firmware

Unauthorized modifications to boot firmware may indicate a sophisticated, targeted attack. These types of targeted attacks can result in a permanent denial of service or a persistent malicious code presence. These situations can occur if the firmware is corrupted or malicious code is embedded in the firmware. System components can protect the integrity of boot firmware in organizational systems by verifying the integ

03.14.11EActive

Integration of Detection and Response

Integrating detection and response ensures that detected events are tracked, monitored, corrected, and available for historical purposes. Maintaining historical records is important to identify and discern adversary actions over an extended time period and for possible legal actions. Security-relevant changes include unauthorized changes to established configuration settings or the unauthorized elevation of system pr

03.14.12EActive

Information Input Validation

Checking the valid syntax and semantics of system inputs—including character set, length, numerical range, and acceptable values—verifies that inputs match specified definitions for format and content. Valid inputs are likely to vary from field to field within a software application. Applications typically follow well-defined protocols that use structured messages (i.e., commands or queries) to communicate between so

03.14.13EActive

Error Handling

Organizations consider the structure and content of error messages. The extent to which systems can handle error conditions is guided and informed by organizational policy and operational requirements. Exploitable information includes stack traces and implementation details; erroneous logon attempts with passwords mistakenly entered as the username; mission or business information that can be derived from, if not sta

03.14.14EActive

Memory Protection

Some adversaries launch attacks with the intent of executing code in non-executable regions of memory or in memory locations that are prohibited. The safeguards used to protect memory include data execution prevention and address space layout randomization (ASLR). Data execution prevention safeguards can be hardware- or software-enforced with hardware enforcement providing the greater strength of mechanism. This requ

03.14.15EActive

Non-Persistent System Components and Services

Implementation of non-persistent components and services mitigates risk from advanced persistent threats (APTs) by reducing the targeting capability of adversaries (i.e., window of opportunity and available attack surface) to initiate and complete attacks. By implementing the concept of non-persistence for selected system components and services, organizations can provide a trusted computing resource for a specific t

03.14.16EActive

Tainting

Many cyber-attacks target organizational information or information that the organization holds on behalf of other entities with the intent to exfiltrate that information. In addition, insider attacks and erroneous user procedures can remove information from the system in violation of organizational policies. Tainting approaches can range from passive to active. A passive tainting approach can be as simple as adding

03.14.17EActive

System-Generated Alerts

Alerts may be generated from different sources internal to the system, including audit records, inputs from malicious code protection mechanisms, intrusion detection or prevention mechanisms, or boundary protection devices such as firewalls, gateways, and routers. Compromise indicators could include CUI being accessed by unauthorized users or when CUI traverses architecture outside of defined data flows. Alerts can b

03.14.18EActive

Automated Organization-Generated Alerts

Organization-generated alerts are focused on information sources that are external to the system, such as suspicious activity reports and reports on potential insider threats. Organizational personnel on the system alert notification list include system administrators, mission or business owners, system owners, chief information security officers, and system security officers. This requirement enhances SP 800-171 req

03.14.19EActive

Wireless Intrusion Detection

Wireless signals may radiate beyond organizational facilities. Organizations proactively search for unauthorized wireless connections, including the conduct of thorough scans for unauthorized wireless access points. Wireless scans are not limited to those areas within facilities containing systems but also include areas outside of facilities to verify that unauthorized wireless access points are not connected to orga