Control statement
- a.Employ integrity verification tools to detect unauthorized changes to the following software, firmware, and information: [Organization-defined: organization-defined software, firmware, and information] ; and
- b.Take the following actions when unauthorized changes to the software, firmware, and information are detected: [Organization-defined: organization-defined actions].
Discussion
Unauthorized changes to software, firmware, and information can occur due to errors or malicious activity. Software includes operating systems (with key internal components, such as kernels or drivers), middleware, and applications. Firmware interfaces include Unified Extensible Firmware Interface (UEFI) and Basic Input/Output System (BIOS). Information includes personally identifiable information and metadata that contains security and privacy attributes associated with information. Integrity-checking mechanisms—including parity checks, cyclical redundancy checks, cryptographic hashes, and associated tools—can automatically monitor the integrity of systems and hosted applications.
Organization-defined parameters
These values must be resolved through the organization’s tailoring and governance process. Bracketed parameter references in the control text identify where a decision is required.
From control text to operational evidence
Use Software, Firmware, and Information Integrity as a testable risk decision. Translate the official statement into accountable people, repeatable processes, configured technology, and evidence that demonstrates the outcome over time. In this family, pay particular attention to flaw remediation, malicious-code protection, monitoring, integrity, and trustworthy information handling.
Implementation workflow
- Define the control boundary, responsible owner, inherited portions, and systems or processes in scope.
- Resolve each organization-defined parameter before declaring the control implemented.
- Document how the implementation satisfies every clause of the official control statement.
- Collect evidence as a normal byproduct of operation rather than only before an assessment.
- Review exceptions, changes, and monitoring results on a risk-based cadence.
Evidence examples
- patch and remediation records
- malware protection configuration
- monitoring alerts and response records
- integrity validation and exception reports
Common failure patterns
- patch compliance hides unsupported assets
- alerts generated without response ownership
- exceptions never expire
- integrity monitoring excludes critical configurations
Questions practitioners should ask
- What risk decision is this control intended to support in this system?
- Which parts are implemented locally, inherited, shared, or not applicable—and what evidence supports that decision?
- Do the documented narrative, deployed configuration, operating process, and collected evidence agree?
- What event or threshold requires the implementation to be reviewed or changed?
Assessment objectives and methods
Show the assessment objective
- SI-07a.
- SI-07a.[01]integrity verification tools are employed to detect unauthorized changes to [Organization-defined: software];
- SI-07a.[02]integrity verification tools are employed to detect unauthorized changes to [Organization-defined: firmware];
- SI-07a.[03]integrity verification tools are employed to detect unauthorized changes to [Organization-defined: information];
- SI-07b.
- SI-07b.[01][Organization-defined: actions] are taken when unauthorized changes to the software, are detected;
- SI-07b.[02][Organization-defined: actions] are taken when unauthorized changes to the firmware are detected;
- SI-07b.[03][Organization-defined: actions] are taken when unauthorized changes to the information are detected.
Examine
- System and information integrity policy
- system and information integrity procedures
- procedures addressing software, firmware, and information integrity
- personally identifiable information processing policy
- system design documentation
- system configuration settings and associated documentation
- integrity verification tools and associated documentation
- records generated or triggered by integrity verification tools regarding unauthorized software, firmware, and information changes
- system audit records
- system security plan
- privacy plan
- other relevant documents or records
Interview
- Organizational personnel responsible for software, firmware, and/or information integrity
- organizational personnel with information security and privacy responsibilities
- system/network administrators
Test
- Software, firmware, and information integrity verification tools
Related controls
These relationships come from the official OSCAL catalog. They indicate useful dependencies or context, not automatic inheritance or equivalence.
Related NIST SP 800-172 requirements
These Rev. 3 requirements cite this base control or one of its enhancements as a source. The relationship does not by itself determine contractual applicability or complete implementation.
Control enhancements
Enhancements add specificity, strength, or scope to the base control. Baseline badges show explicit selections in the official SP 800-53B OSCAL profiles.
SI-7(1) — Integrity Checks
Perform an integrity check of [Organization-defined: organization-defined software, firmware, and information] [Organization-defined: si-7.1_prm_2].
Official discussion
Security-relevant events include the identification of new threats to which organizational systems are susceptible and the installation of new hardware, software, or firmware. Transitional states include system startup, restart, shutdown, and abort.
Organization-defined parameters (16)
Assessment objectives and methods
- SI-07(01)[01]an integrity check of [Organization-defined: software] is performed [Organization-defined: si-07.01_odp.02];
- SI-07(01)[02]an integrity check of [Organization-defined: firmware] is performed [Organization-defined: si-07.01_odp.06];
- SI-07(01)[03]an integrity check of [Organization-defined: information] is performed [Organization-defined: si-07.01_odp.10].
Examine
- System and information integrity policy
- system and information integrity procedures
- procedures addressing software, firmware, and information integrity testing
- system design documentation
- system configuration settings and associated documentation
- integrity verification tools and associated documentation
- records of integrity scans
- system security plan
- other relevant documents or records
Interview
- Organizational personnel responsible for software, firmware, and/or information integrity
- organizational personnel with information security responsibilities
- system/network administrators
- system developer
Test
- Software, firmware, and information integrity verification tools
SI-7(2) — Automated Notifications of Integrity Violations
Employ automated tools that provide notification to [Organization-defined: personnel or roles] upon discovering discrepancies during integrity verification.
Official discussion
The employment of automated tools to report system and information integrity violations and to notify organizational personnel in a timely matter is essential to effective risk response. Personnel with an interest in system and information integrity violations include mission and business owners, system owners, senior agency information security official, senior agency official for privacy, system administrators, software developers, systems integrators, information security officers, and privacy officers.
Organization-defined parameters (1)
Assessment objectives and methods
automated tools that provide notification to [Organization-defined: personnel or roles] upon discovering discrepancies during integrity verification are employed.
Examine
- System and information integrity policy
- system and information integrity procedures
- procedures addressing software, firmware, and information integrity
- personally identifiable information processing policy
- system design documentation
- system configuration settings and associated documentation
- integrity verification tools and associated documentation
- records of integrity scans
- automated tools supporting alerts and notifications for integrity discrepancies
- notifications provided upon discovering discrepancies during integrity verifications
- system audit records
- system security plan
- privacy plan
- other relevant documents or records
Interview
- Organizational personnel responsible for software, firmware, and/or information integrity
- organizational personnel with information security and privacy responsibilities
- system administrators
- software developers
Test
- Software, firmware, and information integrity verification tools
- mechanisms providing integrity discrepancy notifications
SI-7(3) — Centrally Managed Integrity Tools
Employ centrally managed integrity verification tools.
Official discussion
Centrally managed integrity verification tools provides greater consistency in the application of such tools and can facilitate more comprehensive coverage of integrity verification actions.
Assessment objectives and methods
centrally managed integrity verification tools are employed.
Examine
- System and information integrity policy
- system and information integrity procedures
- procedures addressing software, firmware, and information integrity
- system design documentation
- system configuration settings and associated documentation
- integrity verification tools and associated documentation
- records of integrity scans
- system security plan
- other relevant documents or records
Interview
- Organizational personnel responsible for the central management of integrity verification tools
- organizational personnel with information security responsibilities
Test
- Mechanisms supporting and/or implementing the central management of integrity verification tools
Related controls
SI-7(4) — Tamper-evident Packaging
This enhancement is marked withdrawn in the official OSCAL catalog. Related-control metadata below may identify where its intent was incorporated.
SI-7(5) — Automated Response to Integrity Violations
Automatically [Organization-defined: si-07.05_odp.01] when integrity violations are discovered.
Official discussion
Organizations may define different integrity-checking responses by type of information, specific information, or a combination of both. Types of information include firmware, software, and user data. Specific information includes boot firmware for certain types of machines. The automatic implementation of controls within organizational systems includes reversing the changes, halting the system, or triggering audit alerts when unauthorized modifications to critical security files occur.
Organization-defined parameters (2)
Assessment objectives and methods
[Organization-defined: si-07.05_odp.01] are automatically performed when integrity violations are discovered.
Examine
- System and information integrity policy
- system and information integrity procedures
- procedures addressing software, firmware, and information integrity
- system design documentation
- system configuration settings and associated documentation
- integrity verification tools and associated documentation
- records of integrity scans
- records of integrity checks and responses to integrity violations
- audit records
- system security plan
- other relevant documents or records
Interview
- Organizational personnel responsible for software, firmware, and/or information integrity
- organizational personnel with information security responsibilities
- system/network administrators
- system developer
Test
- Software, firmware, and information integrity verification tools
- mechanisms providing an automated response to integrity violations
- mechanisms supporting and/or implementing security safeguards to be implemented when integrity violations are discovered
SI-7(6) — Cryptographic Protection
Implement cryptographic mechanisms to detect unauthorized changes to software, firmware, and information.
Official discussion
Cryptographic mechanisms used to protect integrity include digital signatures and the computation and application of signed hashes using asymmetric cryptography, protecting the confidentiality of the key used to generate the hash, and using the public key to verify the hash information. Organizations that employ cryptographic mechanisms also consider cryptographic key management solutions.
Assessment objectives and methods
- SI-07(06)[01]cryptographic mechanisms are implemented to detect unauthorized changes to software;
- SI-07(06)[02]cryptographic mechanisms are implemented to detect unauthorized changes to firmware;
- SI-07(06)[03]cryptographic mechanisms are implemented to detect unauthorized changes to information.
Examine
- System and information integrity policy
- system and information integrity procedures
- procedures addressing software, firmware, and information integrity
- system design documentation
- system configuration settings and associated documentation
- cryptographic mechanisms and associated documentation
- records of detected unauthorized changes to software, firmware, and information
- system audit records
- system security plan
- other relevant documents or records
Interview
- Organizational personnel responsible for software, firmware, and/or information integrity
- organizational personnel with information security responsibilities
- system/network administrators
- system developer
Test
- Software, firmware, and information integrity verification tools
- cryptographic mechanisms implementing software, firmware, and information integrity
Related controls
SI-7(7) — Integration of Detection and Response
Incorporate the detection of the following unauthorized changes into the organizational incident response capability: [Organization-defined: changes].
Official discussion
Integrating detection and response helps to ensure that detected events are tracked, monitored, corrected, and available for historical purposes. Maintaining historical records is important for being able to identify and discern adversary actions over an extended time period and for possible legal actions. Security-relevant changes include unauthorized changes to established configuration settings or the unauthorized elevation of system privileges.
Organization-defined parameters (1)
Assessment objectives and methods
the detection of [Organization-defined: changes] are incorporated into the organizational incident response capability.
Examine
- System and information integrity policy
- system and information integrity procedures
- procedures addressing software, firmware, and information integrity
- procedures addressing incident response
- system design documentation
- system configuration settings and associated documentation
- incident response records
- audit records
- system security plan
- other relevant documents or records
Interview
- Organizational personnel responsible for software, firmware, and/or information integrity
- organizational personnel with information security responsibilities
- organizational personnel with incident response responsibilities
Test
- Organizational processes for incorporating the detection of unauthorized security-relevant changes into the incident response capability
- software, firmware, and information integrity verification tools
- mechanisms supporting and/or implementing the incorporation of detection of unauthorized security-relevant changes into the incident response capability
Related controls
SI-7(8) — Auditing Capability for Significant Events
Upon detection of a potential integrity violation, provide the capability to audit the event and initiate the following actions: [Organization-defined: si-07.08_odp.01].
Official discussion
Organizations select response actions based on types of software, specific software, or information for which there are potential integrity violations.
Organization-defined parameters (3)
Assessment objectives and methods
- SI-07(08)[01]the capability to audit an event upon the detection of a potential integrity violation is provided;
- SI-07(08)[02][Organization-defined: si-07.08_odp.01] is/are initiated upon the detection of a potential integrity violation.
Examine
- System and information integrity policy
- system and information integrity procedures
- procedures addressing software, firmware, and information integrity
- system design documentation
- system configuration settings and associated documentation
- integrity verification tools and associated documentation
- records of integrity scans
- incident response records
- list of security-relevant changes to the system
- automated tools supporting alerts and notifications if unauthorized security changes are detected
- system audit records
- system security plan
- other relevant documents or records
Interview
- Organizational personnel responsible for software, firmware, and/or information integrity
- organizational personnel with information security responsibilities
- system/network administrators
- system developer
Test
- Software, firmware, and information integrity verification tools
- mechanisms supporting and/or implementing the capability to audit potential integrity violations
- mechanisms supporting and/or implementing alerts about potential integrity violations
Related controls
SI-7(9) — Verify Boot Process
Verify the integrity of the boot process of the following system components: [Organization-defined: system components].
Official discussion
Ensuring the integrity of boot processes is critical to starting system components in known, trustworthy states. Integrity verification mechanisms provide a level of assurance that only trusted code is executed during boot processes.
Organization-defined parameters (1)
Assessment objectives and methods
the integrity of the boot process of [Organization-defined: system components] is verified.
Examine
- System and information integrity policy
- system and information integrity procedures
- procedures addressing software, firmware, and information integrity
- system design documentation
- system configuration settings and associated documentation
- integrity verification tools and associated documentation
- documentation
- records of integrity verification scans
- system audit records
- system security plan
- other relevant documents or records
Interview
- Organizational personnel responsible for software, firmware, and/or information integrity
- organizational personnel with information security responsibilities
- system developer
Test
- Software, firmware, and information integrity verification tools
- mechanisms supporting and/or implementing integrity verification of the boot process
Related controls
SI-7(10) — Protection of Boot Firmware
Implement the following mechanisms to protect the integrity of boot firmware in [Organization-defined: system components]: [Organization-defined: mechanisms].
Official discussion
Unauthorized modifications to boot firmware may indicate a sophisticated, targeted attack. These types of targeted attacks can result in a permanent denial of service or a persistent malicious code presence. These situations can occur if the firmware is corrupted or if the malicious code is embedded within the firmware. System components can protect the integrity of boot firmware in organizational systems by verifying the integrity and authenticity of all updates to the firmware prior to applying changes to the system component and preventing unauthorized processes from modifying the boot firmware.
Organization-defined parameters (2)
Assessment objectives and methods
[Organization-defined: mechanisms] are implemented to protect the integrity of boot firmware in [Organization-defined: system components].
Examine
- System and information integrity policy
- system and information integrity procedures
- procedures addressing software, firmware, and information integrity
- system design documentation
- system configuration settings and associated documentation
- integrity verification tools and associated documentation
- records of integrity verification scans
- system audit records
- system security plan
- other relevant documents or records
Interview
- Organizational personnel responsible for software, firmware, and/or information integrity
- organizational personnel with information security responsibilities
- system/network administrators
- system developer
Test
- Software, firmware, and information integrity verification tools
- mechanisms supporting and/or implementing protection of the integrity of boot firmware
- safeguards implementing protection of the integrity of boot firmware
Related controls
SI-7(11) — Confined Environments with Limited Privileges
This enhancement is marked withdrawn in the official OSCAL catalog. Related-control metadata below may identify where its intent was incorporated.
SI-7(12) — Integrity Verification
Require that the integrity of the following user-installed software be verified prior to execution: [Organization-defined: user-installed software].
Official discussion
Organizations verify the integrity of user-installed software prior to execution to reduce the likelihood of executing malicious code or programs that contains errors from unauthorized modifications. Organizations consider the source of the software, ensuring the software and updates come from authorized sources and/or sites, and the practicality of approaches to verifying software integrity, including the availability of trustworthy checksums from software developers and vendors.
Organization-defined parameters (1)
Assessment objectives and methods
the integrity of [Organization-defined: user-installed software] is verified prior to execution.
Examine
- System and information integrity policy
- system and information integrity procedures
- procedures addressing software, firmware, and information integrity
- system design documentation
- system configuration settings and associated documentation
- integrity verification records
- system audit records
- system security plan
- other relevant documents or records
Interview
- Organizational personnel responsible for software, firmware, and/or information integrity
- organizational personnel with information security responsibilities
Test
- Software, firmware, and information integrity verification tools
- mechanisms supporting and/or implementing verification of the integrity of user-installed software prior to execution
Related controls
SI-7(13) — Code Execution in Protected Environments
This enhancement is marked withdrawn in the official OSCAL catalog. Related-control metadata below may identify where its intent was incorporated.
SI-7(14) — Binary or Machine Executable Code
This enhancement is marked withdrawn in the official OSCAL catalog. Related-control metadata below may identify where its intent was incorporated.
SI-7(15) — Code Authentication
Implement cryptographic mechanisms to authenticate the following software or firmware components prior to installation: [Organization-defined: software or firmware components].
Official discussion
Cryptographic authentication includes verifying that software or firmware components have been digitally signed using certificates recognized and approved by organizations. Code signing is an effective method to protect against malicious code. Organizations that employ cryptographic mechanisms also consider cryptographic key management solutions.
Organization-defined parameters (1)
Assessment objectives and methods
cryptographic mechanisms are implemented to authenticate [Organization-defined: software or firmware components] prior to installation.
Examine
- System and information integrity policy
- system and information integrity procedures
- procedures addressing software, firmware, and information integrity
- system design documentation
- system configuration settings and associated documentation
- cryptographic mechanisms and associated documentation
- system audit records
- system security plan
- other relevant documents or records
Interview
- Organizational personnel responsible for software, firmware, and/or information integrity
- organizational personnel with information security responsibilities
- system/network administrators
- system developer
Test
- Cryptographic mechanisms authenticating software and firmware prior to installation
Related controls
SI-7(16) — Time Limit on Process Execution Without Supervision
Prohibit processes from executing without supervision for more than [Organization-defined: time period].
Official discussion
Placing a time limit on process execution without supervision is intended to apply to processes for which typical or normal execution periods can be determined and situations in which organizations exceed such periods. Supervision includes timers on operating systems, automated responses, and manual oversight and response when system process anomalies occur.
Organization-defined parameters (1)
Assessment objectives and methods
processes are prohibited from executing without supervision for more than [Organization-defined: time period].
Examine
- System and information integrity policy
- system and information integrity procedures
- procedures addressing software and information integrity
- system design documentation
- system configuration settings and associated documentation
- system audit records
- system security plan
- other relevant documents or records
Interview
- Organizational personnel responsible for software, firmware, and/or information integrity
- organizational personnel with information security responsibilities
- system/network administrators
- system developer
Test
- Software, firmware, and information integrity verification tools
- mechanisms supporting and/or implementing time limits on process execution without supervision
SI-7(17) — Runtime Application Self-protection
Implement [Organization-defined: controls] for application self-protection at runtime.
Official discussion
Runtime application self-protection employs runtime instrumentation to detect and block the exploitation of software vulnerabilities by taking advantage of information from the software in execution. Runtime exploit prevention differs from traditional perimeter-based protections such as guards and firewalls which can only detect and block attacks by using network information without contextual awareness. Runtime application self-protection technology can reduce the susceptibility of software to attacks by monitoring its inputs and blocking those inputs that could allow attacks. It can also help protect the runtime environment from unwanted changes and tampering. When a threat is detected, runtime application self-protection technology can prevent exploitation and take other actions (e.g., sending a warning message to the user, terminating the user's session, terminating the application, or sending an alert to organizational personnel). Runtime application self-protection solutions can be deployed in either a monitor or protection mode.
Organization-defined parameters (1)
Assessment objectives and methods
[Organization-defined: controls] are implemented for application self-protection at runtime.
Examine
- System and information integrity policy
- system and information integrity procedures
- procedures addressing software and information integrity
- system design documentation
- system configuration settings and associated documentation
- list of known vulnerabilities addressed by runtime instrumentation
- system security plan
- other relevant documents or records
Interview
- Organizational personnel responsible for software, firmware, and/or information integrity
- organizational personnel with information security responsibilities
- system/network administrators
- system developer
Test
- Software, firmware, and information integrity verification tools
- mechanisms supporting and/or implementing runtime application self-protection
Related controls
Authoritative sources
Bare Metal Cyber is an independent educational publisher and is not affiliated with or endorsed by NIST. Official control requirements and interpretations remain with NIST and the responsible authorizing organization.