Control statement
- a.Verify the correct operation of [Organization-defined: organization-defined security and privacy functions];
- b.Perform the verification of the functions specified in SI-6a [Organization-defined: si-06_odp.03];
- c.Alert [Organization-defined: personnel or roles] to failed security and privacy verification tests; and
- d.[Organization-defined: si-06_odp.07] when anomalies are discovered.
Discussion
Transitional states for systems include system startup, restart, shutdown, and abort. System notifications include hardware indicator lights, electronic alerts to system administrators, and messages to local computer consoles. In contrast to security function verification, privacy function verification ensures that privacy functions operate as expected and are approved by the senior agency official for privacy or that privacy attributes are applied or used as expected.
Organization-defined parameters
These values must be resolved through the organization’s tailoring and governance process. Bracketed parameter references in the control text identify where a decision is required.
From control text to operational evidence
Use Security and Privacy Function Verification as a testable risk decision. Translate the official statement into accountable people, repeatable processes, configured technology, and evidence that demonstrates the outcome over time. In this family, pay particular attention to flaw remediation, malicious-code protection, monitoring, integrity, and trustworthy information handling.
Implementation workflow
- Define the control boundary, responsible owner, inherited portions, and systems or processes in scope.
- Resolve each organization-defined parameter before declaring the control implemented.
- Document how the implementation satisfies every clause of the official control statement.
- Collect evidence as a normal byproduct of operation rather than only before an assessment.
- Review exceptions, changes, and monitoring results on a risk-based cadence.
Evidence examples
- patch and remediation records
- malware protection configuration
- monitoring alerts and response records
- integrity validation and exception reports
Common failure patterns
- patch compliance hides unsupported assets
- alerts generated without response ownership
- exceptions never expire
- integrity monitoring excludes critical configurations
Questions practitioners should ask
- What risk decision is this control intended to support in this system?
- Which parts are implemented locally, inherited, shared, or not applicable—and what evidence supports that decision?
- Do the documented narrative, deployed configuration, operating process, and collected evidence agree?
- What event or threshold requires the implementation to be reviewed or changed?
Assessment objectives and methods
Show the assessment objective
- SI-06a.
- SI-06a.[01][Organization-defined: security functions] are verified to be operating correctly;
- SI-06a.[02][Organization-defined: privacy functions] are verified to be operating correctly;
- SI-06b.
- SI-06b.[01][Organization-defined: security functions] are verified [Organization-defined: si-06_odp.03];
- SI-06b.[02][Organization-defined: privacy functions] are verified [Organization-defined: si-06_odp.03];
- SI-06c.
- SI-06c.[01][Organization-defined: personnel or roles] is/are alerted to failed security verification tests;
- SI-06c.[02][Organization-defined: personnel or roles] is/are alerted to failed privacy verification tests;
- SI-06d.[Organization-defined: si-06_odp.07] is/are initiated when anomalies are discovered.
Examine
- System and information integrity policy
- system and information integrity procedures
- procedures addressing security and privacy function verification
- system design documentation
- system configuration settings and associated documentation
- alerts/notifications of failed security verification tests
- list of system transition states requiring security functionality verification
- system audit records
- system security plan
- privacy plan
- other relevant documents or records
Interview
- Organizational personnel with security and privacy function verification responsibilities
- organizational personnel implementing, operating, and maintaining the system
- system/network administrators
- organizational personnel with information security and privacy responsibilities
- system developer
Test
- Organizational processes for security and privacy function verification
- mechanisms supporting and/or implementing the security and privacy function verification capability
Related controls
These relationships come from the official OSCAL catalog. They indicate useful dependencies or context, not automatic inheritance or equivalence.
Control enhancements
Enhancements add specificity, strength, or scope to the base control. Baseline badges show explicit selections in the official SP 800-53B OSCAL profiles.
SI-6(1) — Notification of Failed Security Tests
This enhancement is marked withdrawn in the official OSCAL catalog. Related-control metadata below may identify where its intent was incorporated.
SI-6(2) — Automation Support for Distributed Testing
Implement automated mechanisms to support the management of distributed security and privacy function testing.
Official discussion
The use of automated mechanisms to support the management of distributed function testing helps to ensure the integrity, timeliness, completeness, and efficacy of such testing.
Assessment objectives and methods
- SI-06(02)[01]automated mechanisms are implemented to support the management of distributed security function testing;
- SI-06(02)[02]automated mechanisms are implemented to support the management of distributed privacy function testing.
Examine
- System and information integrity policy
- system and information integrity procedures
- procedures addressing security and privacy function verification
- system design documentation
- system configuration settings and associated documentation
- system audit records
- system security plan
- privacy plan
- other relevant documents or records
Interview
- Organizational personnel with security and privacy function verification responsibilities
- organizational personnel implementing, operating, and maintaining the system
- system/network administrators
- organizational personnel with information security and privacy responsibilities
Test
- Organizational processes for security and privacy function verification
- automated mechanisms supporting and/or implementing the management of distributed security and privacy testing
Related controls
SI-6(3) — Report Verification Results
Report the results of security and privacy function verification to [Organization-defined: personnel or roles].
Official discussion
Organizational personnel with potential interest in the results of the verification of security and privacy functions include systems security officers, senior agency information security officers, and senior agency officials for privacy.
Organization-defined parameters (1)
Assessment objectives and methods
- SI-06(03)[01]the results of security function verification are reported to [Organization-defined: personnel or roles];
- SI-06(03)[02]the results of privacy function verification are reported to [Organization-defined: personnel or roles].
Examine
- System and information integrity policy
- system and information integrity procedures
- procedures addressing security and privacy function verification
- system design documentation
- system configuration settings and associated documentation
- reports of security and privacy function verification results
- system audit records
- system security plan
- privacy plan
- other relevant documents or records
Interview
- Organizational personnel with security and privacy function verification responsibilities
- organizational personnel who are recipients of security and privacy function verification reports
- organizational personnel with information security and privacy responsibilities
Test
- Organizational processes for reporting security and privacy function verification results
- mechanisms supporting and/or implementing the reporting of security and privacy function verification results
Related controls
Authoritative sources
Bare Metal Cyber is an independent educational publisher and is not affiliated with or endorsed by NIST. Official control requirements and interpretations remain with NIST and the responsible authorizing organization.