Knowledge is Power

Sitewide Search

Search Bare Metal Cyber

Search courses, individual lessons, wiki entries, books, podcasts, magazine articles, Daily Cyber News, and Darwin.

NIST SP 800-53 Learning Center

SI-6 — Security and Privacy Function Verification

Read the official control and assessment content, then use the separately labeled Bare Metal Cyber perspective to connect the requirement to implementation, evidence, and sustained operation.

3Enhancements
9Parameters
1Baseline memberships
3Assessment methods

SI — System and Information Integrity · NIST SP 800-53 Release 5.2.0

High
Official NIST control content

Control statement

  1. a.Verify the correct operation of [Organization-defined: organization-defined security and privacy functions];
  2. b.Perform the verification of the functions specified in SI-6a [Organization-defined: si-06_odp.03];
  3. c.Alert [Organization-defined: personnel or roles] to failed security and privacy verification tests; and
  4. d.[Organization-defined: si-06_odp.07] when anomalies are discovered.
Official NIST discussion

Discussion

Transitional states for systems include system startup, restart, shutdown, and abort. System notifications include hardware indicator lights, electronic alerts to system administrators, and messages to local computer consoles. In contrast to security function verification, privacy function verification ensures that privacy functions operate as expected and are approved by the senior agency official for privacy or that privacy attributes are applied or used as expected.

Official OSCAL parameters

Organization-defined parameters

These values must be resolved through the organization’s tailoring and governance process. Bracketed parameter references in the control text identify where a decision is required.

organization-defined security and privacy functions
security functionssecurity functions to be verified for correct operation are defined;
privacy functionsprivacy functions to be verified for correct operation are defined;
si-06_odp.03
system transitional statessystem transitional states requiring the verification of security and privacy functions are defined; (if selected)
frequencyfrequency at which to verify the correct operation of security and privacy functions is defined; (if selected)
personnel or rolespersonnel or roles to be alerted of failed security and privacy verification tests is/are defined;
si-06_odp.07
alternative action(s)alternative action(s) to be performed when anomalies are discovered are defined (if selected);
Original Bare Metal Cyber perspective

From control text to operational evidence

Use Security and Privacy Function Verification as a testable risk decision. Translate the official statement into accountable people, repeatable processes, configured technology, and evidence that demonstrates the outcome over time. In this family, pay particular attention to flaw remediation, malicious-code protection, monitoring, integrity, and trustworthy information handling.

Implementation workflow

  • Define the control boundary, responsible owner, inherited portions, and systems or processes in scope.
  • Resolve each organization-defined parameter before declaring the control implemented.
  • Document how the implementation satisfies every clause of the official control statement.
  • Collect evidence as a normal byproduct of operation rather than only before an assessment.
  • Review exceptions, changes, and monitoring results on a risk-based cadence.

Evidence examples

  • patch and remediation records
  • malware protection configuration
  • monitoring alerts and response records
  • integrity validation and exception reports

Common failure patterns

  • patch compliance hides unsupported assets
  • alerts generated without response ownership
  • exceptions never expire
  • integrity monitoring excludes critical configurations

Questions practitioners should ask

  • What risk decision is this control intended to support in this system?
  • Which parts are implemented locally, inherited, shared, or not applicable—and what evidence supports that decision?
  • Do the documented narrative, deployed configuration, operating process, and collected evidence agree?
  • What event or threshold requires the implementation to be reviewed or changed?
Official NIST SP 800-53A content

Assessment objectives and methods

Show the assessment objective
  1. SI-06a.
    1. SI-06a.[01][Organization-defined: security functions] are verified to be operating correctly;
    2. SI-06a.[02][Organization-defined: privacy functions] are verified to be operating correctly;
  2. SI-06b.
    1. SI-06b.[01][Organization-defined: security functions] are verified [Organization-defined: si-06_odp.03];
    2. SI-06b.[02][Organization-defined: privacy functions] are verified [Organization-defined: si-06_odp.03];
  3. SI-06c.
    1. SI-06c.[01][Organization-defined: personnel or roles] is/are alerted to failed security verification tests;
    2. SI-06c.[02][Organization-defined: personnel or roles] is/are alerted to failed privacy verification tests;
  4. SI-06d.[Organization-defined: si-06_odp.07] is/are initiated when anomalies are discovered.

Examine

  • System and information integrity policy
  • system and information integrity procedures
  • procedures addressing security and privacy function verification
  • system design documentation
  • system configuration settings and associated documentation
  • alerts/notifications of failed security verification tests
  • list of system transition states requiring security functionality verification
  • system audit records
  • system security plan
  • privacy plan
  • other relevant documents or records

Interview

  • Organizational personnel with security and privacy function verification responsibilities
  • organizational personnel implementing, operating, and maintaining the system
  • system/network administrators
  • organizational personnel with information security and privacy responsibilities
  • system developer

Test

  • Organizational processes for security and privacy function verification
  • mechanisms supporting and/or implementing the security and privacy function verification capability
Official relationships

Related controls

These relationships come from the official OSCAL catalog. They indicate useful dependencies or context, not automatic inheritance or equivalence.

Official NIST enhancements

Control enhancements

Enhancements add specificity, strength, or scope to the base control. Baseline badges show explicit selections in the official SP 800-53B OSCAL profiles.

Official NIST control enhancement

SI-6(1) — Notification of Failed Security Tests

Withdrawn

This enhancement is marked withdrawn in the official OSCAL catalog. Related-control metadata below may identify where its intent was incorporated.

Official NIST control enhancement

SI-6(2) — Automation Support for Distributed Testing

Implement automated mechanisms to support the management of distributed security and privacy function testing.

Official discussion

The use of automated mechanisms to support the management of distributed function testing helps to ensure the integrity, timeliness, completeness, and efficacy of such testing.

Assessment objectives and methods
  1. SI-06(02)[01]automated mechanisms are implemented to support the management of distributed security function testing;
  2. SI-06(02)[02]automated mechanisms are implemented to support the management of distributed privacy function testing.

Examine

  • System and information integrity policy
  • system and information integrity procedures
  • procedures addressing security and privacy function verification
  • system design documentation
  • system configuration settings and associated documentation
  • system audit records
  • system security plan
  • privacy plan
  • other relevant documents or records

Interview

  • Organizational personnel with security and privacy function verification responsibilities
  • organizational personnel implementing, operating, and maintaining the system
  • system/network administrators
  • organizational personnel with information security and privacy responsibilities

Test

  • Organizational processes for security and privacy function verification
  • automated mechanisms supporting and/or implementing the management of distributed security and privacy testing
Related controls
Official NIST control enhancement

SI-6(3) — Report Verification Results

Report the results of security and privacy function verification to [Organization-defined: personnel or roles].

Official discussion

Organizational personnel with potential interest in the results of the verification of security and privacy functions include systems security officers, senior agency information security officers, and senior agency officials for privacy.

Organization-defined parameters (1)
personnel or rolespersonnel or roles designated to receive the results of security and privacy function verification is/are defined;
Assessment objectives and methods
  1. SI-06(03)[01]the results of security function verification are reported to [Organization-defined: personnel or roles];
  2. SI-06(03)[02]the results of privacy function verification are reported to [Organization-defined: personnel or roles].

Examine

  • System and information integrity policy
  • system and information integrity procedures
  • procedures addressing security and privacy function verification
  • system design documentation
  • system configuration settings and associated documentation
  • reports of security and privacy function verification results
  • system audit records
  • system security plan
  • privacy plan
  • other relevant documents or records

Interview

  • Organizational personnel with security and privacy function verification responsibilities
  • organizational personnel who are recipients of security and privacy function verification reports
  • organizational personnel with information security and privacy responsibilities

Test

  • Organizational processes for reporting security and privacy function verification results
  • mechanisms supporting and/or implementing the reporting of security and privacy function verification results
Related controls
Source record

Authoritative sources