Knowledge is Power

Sitewide Search

Search Bare Metal Cyber

Search exact control and technique identifiers, Cyber Wiki articles, framework records, playbooks, books, podcasts, Academy courses, and individual lessons.

NIST SP 800-53 Learning Center

SI-7 — Software, Firmware, and Information Integrity

Read the official control and assessment content, then use the separately labeled Bare Metal Cyber perspective to connect the requirement to implementation, evidence, and sustained operation.

17Enhancements
8Parameters
2Baseline memberships
3Assessment methods

SI — System and Information Integrity · NIST SP 800-53 Release 5.2.0

ModerateHigh
Official NIST control content

Control statement

  1. a.Employ integrity verification tools to detect unauthorized changes to the following software, firmware, and information: [Organization-defined: organization-defined software, firmware, and information] ; and
  2. b.Take the following actions when unauthorized changes to the software, firmware, and information are detected: [Organization-defined: organization-defined actions].
Official NIST discussion

Discussion

Unauthorized changes to software, firmware, and information can occur due to errors or malicious activity. Software includes operating systems (with key internal components, such as kernels or drivers), middleware, and applications. Firmware interfaces include Unified Extensible Firmware Interface (UEFI) and Basic Input/Output System (BIOS). Information includes personally identifiable information and metadata that contains security and privacy attributes associated with information. Integrity-checking mechanisms—including parity checks, cyclical redundancy checks, cryptographic hashes, and associated tools—can automatically monitor the integrity of systems and hosted applications.

Official OSCAL parameters

Organization-defined parameters

These values must be resolved through the organization’s tailoring and governance process. Bracketed parameter references in the control text identify where a decision is required.

organization-defined software, firmware, and information
organization-defined actions
softwaresoftware requiring integrity verification tools to be employed to detect unauthorized changes is defined;
firmwarefirmware requiring integrity verification tools to be employed to detect unauthorized changes is defined;
informationinformation requiring integrity verification tools to be employed to detect unauthorized changes is defined;
actionsactions to be taken when unauthorized changes to software are detected are defined;
actionsactions to be taken when unauthorized changes to firmware are detected are defined;
actionsactions to be taken when unauthorized changes to information are detected are defined;
Original Bare Metal Cyber perspective

From control text to operational evidence

Use Software, Firmware, and Information Integrity as a testable risk decision. Translate the official statement into accountable people, repeatable processes, configured technology, and evidence that demonstrates the outcome over time. In this family, pay particular attention to flaw remediation, malicious-code protection, monitoring, integrity, and trustworthy information handling.

Implementation workflow

  • Define the control boundary, responsible owner, inherited portions, and systems or processes in scope.
  • Resolve each organization-defined parameter before declaring the control implemented.
  • Document how the implementation satisfies every clause of the official control statement.
  • Collect evidence as a normal byproduct of operation rather than only before an assessment.
  • Review exceptions, changes, and monitoring results on a risk-based cadence.

Evidence examples

  • patch and remediation records
  • malware protection configuration
  • monitoring alerts and response records
  • integrity validation and exception reports

Common failure patterns

  • patch compliance hides unsupported assets
  • alerts generated without response ownership
  • exceptions never expire
  • integrity monitoring excludes critical configurations

Questions practitioners should ask

  • What risk decision is this control intended to support in this system?
  • Which parts are implemented locally, inherited, shared, or not applicable—and what evidence supports that decision?
  • Do the documented narrative, deployed configuration, operating process, and collected evidence agree?
  • What event or threshold requires the implementation to be reviewed or changed?
Official NIST SP 800-53A content

Assessment objectives and methods

Show the assessment objective
  1. SI-07a.
    1. SI-07a.[01]integrity verification tools are employed to detect unauthorized changes to [Organization-defined: software];
    2. SI-07a.[02]integrity verification tools are employed to detect unauthorized changes to [Organization-defined: firmware];
    3. SI-07a.[03]integrity verification tools are employed to detect unauthorized changes to [Organization-defined: information];
  2. SI-07b.
    1. SI-07b.[01][Organization-defined: actions] are taken when unauthorized changes to the software, are detected;
    2. SI-07b.[02][Organization-defined: actions] are taken when unauthorized changes to the firmware are detected;
    3. SI-07b.[03][Organization-defined: actions] are taken when unauthorized changes to the information are detected.

Examine

  • System and information integrity policy
  • system and information integrity procedures
  • procedures addressing software, firmware, and information integrity
  • personally identifiable information processing policy
  • system design documentation
  • system configuration settings and associated documentation
  • integrity verification tools and associated documentation
  • records generated or triggered by integrity verification tools regarding unauthorized software, firmware, and information changes
  • system audit records
  • system security plan
  • privacy plan
  • other relevant documents or records

Interview

  • Organizational personnel responsible for software, firmware, and/or information integrity
  • organizational personnel with information security and privacy responsibilities
  • system/network administrators

Test

  • Software, firmware, and information integrity verification tools
Official relationships

Related controls

These relationships come from the official OSCAL catalog. They indicate useful dependencies or context, not automatic inheritance or equivalence.

Official CUI requirement crosswalk

Related NIST SP 800-172 requirements

These Rev. 3 requirements cite this base control or one of its enhancements as a source. The relationship does not by itself determine contractual applicability or complete implementation.

Official NIST enhancements

Control enhancements

Enhancements add specificity, strength, or scope to the base control. Baseline badges show explicit selections in the official SP 800-53B OSCAL profiles.

Official NIST control enhancement

SI-7(1) — Integrity Checks

ModerateHigh

Perform an integrity check of [Organization-defined: organization-defined software, firmware, and information] [Organization-defined: si-7.1_prm_2].

Official discussion

Security-relevant events include the identification of new threats to which organizational systems are susceptible and the installation of new hardware, software, or firmware. Transitional states include system startup, restart, shutdown, and abort.

Organization-defined parameters (16)
organization-defined software, firmware, and information
si-7.1_prm_2
organization-defined transitional states or security-relevant events
organization-defined frequency
softwaresoftware on which an integrity check is to be performed is defined;
si-07.01_odp.02
transitional states or security-relevant eventstransitional states or security-relevant events requiring integrity checks (on software) are defined (if selected);
frequencyfrequency with which to perform an integrity check (on software) is defined (if selected);
firmwarefirmware on which an integrity check is to be performed is defined;
si-07.01_odp.06
transitional states or security-relevant eventstransitional states or security-relevant events requiring integrity checks (on firmware) are defined (if selected);
frequencyfrequency with which to perform an integrity check (on firmware) is defined (if selected);
informationinformation on which an integrity check is to be performed is defined;
si-07.01_odp.10
transitional states or security-relevant eventstransitional states or security-relevant events requiring integrity checks (of information) are defined (if selected);
frequencyfrequency with which to perform an integrity check (of information) is defined (if selected);
Assessment objectives and methods
  1. SI-07(01)[01]an integrity check of [Organization-defined: software] is performed [Organization-defined: si-07.01_odp.02];
  2. SI-07(01)[02]an integrity check of [Organization-defined: firmware] is performed [Organization-defined: si-07.01_odp.06];
  3. SI-07(01)[03]an integrity check of [Organization-defined: information] is performed [Organization-defined: si-07.01_odp.10].

Examine

  • System and information integrity policy
  • system and information integrity procedures
  • procedures addressing software, firmware, and information integrity testing
  • system design documentation
  • system configuration settings and associated documentation
  • integrity verification tools and associated documentation
  • records of integrity scans
  • system security plan
  • other relevant documents or records

Interview

  • Organizational personnel responsible for software, firmware, and/or information integrity
  • organizational personnel with information security responsibilities
  • system/network administrators
  • system developer

Test

  • Software, firmware, and information integrity verification tools
Official NIST control enhancement

SI-7(2) — Automated Notifications of Integrity Violations

High

Employ automated tools that provide notification to [Organization-defined: personnel or roles] upon discovering discrepancies during integrity verification.

Official discussion

The employment of automated tools to report system and information integrity violations and to notify organizational personnel in a timely matter is essential to effective risk response. Personnel with an interest in system and information integrity violations include mission and business owners, system owners, senior agency information security official, senior agency official for privacy, system administrators, software developers, systems integrators, information security officers, and privacy officers.

Organization-defined parameters (1)
personnel or rolespersonnel or roles to whom notification is to be provided upon discovering discrepancies during integrity verification is/are defined;
Assessment objectives and methods

automated tools that provide notification to [Organization-defined: personnel or roles] upon discovering discrepancies during integrity verification are employed.

Examine

  • System and information integrity policy
  • system and information integrity procedures
  • procedures addressing software, firmware, and information integrity
  • personally identifiable information processing policy
  • system design documentation
  • system configuration settings and associated documentation
  • integrity verification tools and associated documentation
  • records of integrity scans
  • automated tools supporting alerts and notifications for integrity discrepancies
  • notifications provided upon discovering discrepancies during integrity verifications
  • system audit records
  • system security plan
  • privacy plan
  • other relevant documents or records

Interview

  • Organizational personnel responsible for software, firmware, and/or information integrity
  • organizational personnel with information security and privacy responsibilities
  • system administrators
  • software developers

Test

  • Software, firmware, and information integrity verification tools
  • mechanisms providing integrity discrepancy notifications
Official NIST control enhancement

SI-7(3) — Centrally Managed Integrity Tools

Employ centrally managed integrity verification tools.

Official discussion

Centrally managed integrity verification tools provides greater consistency in the application of such tools and can facilitate more comprehensive coverage of integrity verification actions.

Assessment objectives and methods

centrally managed integrity verification tools are employed.

Examine

  • System and information integrity policy
  • system and information integrity procedures
  • procedures addressing software, firmware, and information integrity
  • system design documentation
  • system configuration settings and associated documentation
  • integrity verification tools and associated documentation
  • records of integrity scans
  • system security plan
  • other relevant documents or records

Interview

  • Organizational personnel responsible for the central management of integrity verification tools
  • organizational personnel with information security responsibilities

Test

  • Mechanisms supporting and/or implementing the central management of integrity verification tools
Related controls
Official NIST control enhancement

SI-7(4) — Tamper-evident Packaging

Withdrawn

This enhancement is marked withdrawn in the official OSCAL catalog. Related-control metadata below may identify where its intent was incorporated.

Official NIST control enhancement

SI-7(5) — Automated Response to Integrity Violations

High

Automatically [Organization-defined: si-07.05_odp.01] when integrity violations are discovered.

Official discussion

Organizations may define different integrity-checking responses by type of information, specific information, or a combination of both. Types of information include firmware, software, and user data. Specific information includes boot firmware for certain types of machines. The automatic implementation of controls within organizational systems includes reversing the changes, halting the system, or triggering audit alerts when unauthorized modifications to critical security files occur.

Organization-defined parameters (2)
si-07.05_odp.01
controlscontrols to be implemented automatically when integrity violations are discovered are defined (if selected);
Assessment objectives and methods

[Organization-defined: si-07.05_odp.01] are automatically performed when integrity violations are discovered.

Examine

  • System and information integrity policy
  • system and information integrity procedures
  • procedures addressing software, firmware, and information integrity
  • system design documentation
  • system configuration settings and associated documentation
  • integrity verification tools and associated documentation
  • records of integrity scans
  • records of integrity checks and responses to integrity violations
  • audit records
  • system security plan
  • other relevant documents or records

Interview

  • Organizational personnel responsible for software, firmware, and/or information integrity
  • organizational personnel with information security responsibilities
  • system/network administrators
  • system developer

Test

  • Software, firmware, and information integrity verification tools
  • mechanisms providing an automated response to integrity violations
  • mechanisms supporting and/or implementing security safeguards to be implemented when integrity violations are discovered
Official NIST control enhancement

SI-7(6) — Cryptographic Protection

Implement cryptographic mechanisms to detect unauthorized changes to software, firmware, and information.

Official discussion

Cryptographic mechanisms used to protect integrity include digital signatures and the computation and application of signed hashes using asymmetric cryptography, protecting the confidentiality of the key used to generate the hash, and using the public key to verify the hash information. Organizations that employ cryptographic mechanisms also consider cryptographic key management solutions.

Assessment objectives and methods
  1. SI-07(06)[01]cryptographic mechanisms are implemented to detect unauthorized changes to software;
  2. SI-07(06)[02]cryptographic mechanisms are implemented to detect unauthorized changes to firmware;
  3. SI-07(06)[03]cryptographic mechanisms are implemented to detect unauthorized changes to information.

Examine

  • System and information integrity policy
  • system and information integrity procedures
  • procedures addressing software, firmware, and information integrity
  • system design documentation
  • system configuration settings and associated documentation
  • cryptographic mechanisms and associated documentation
  • records of detected unauthorized changes to software, firmware, and information
  • system audit records
  • system security plan
  • other relevant documents or records

Interview

  • Organizational personnel responsible for software, firmware, and/or information integrity
  • organizational personnel with information security responsibilities
  • system/network administrators
  • system developer

Test

  • Software, firmware, and information integrity verification tools
  • cryptographic mechanisms implementing software, firmware, and information integrity
Related controls
Official NIST control enhancement

SI-7(7) — Integration of Detection and Response

ModerateHigh

Incorporate the detection of the following unauthorized changes into the organizational incident response capability: [Organization-defined: changes].

Official discussion

Integrating detection and response helps to ensure that detected events are tracked, monitored, corrected, and available for historical purposes. Maintaining historical records is important for being able to identify and discern adversary actions over an extended time period and for possible legal actions. Security-relevant changes include unauthorized changes to established configuration settings or the unauthorized elevation of system privileges.

Organization-defined parameters (1)
changessecurity-relevant changes to the system are defined;
Assessment objectives and methods

the detection of [Organization-defined: changes] are incorporated into the organizational incident response capability.

Examine

  • System and information integrity policy
  • system and information integrity procedures
  • procedures addressing software, firmware, and information integrity
  • procedures addressing incident response
  • system design documentation
  • system configuration settings and associated documentation
  • incident response records
  • audit records
  • system security plan
  • other relevant documents or records

Interview

  • Organizational personnel responsible for software, firmware, and/or information integrity
  • organizational personnel with information security responsibilities
  • organizational personnel with incident response responsibilities

Test

  • Organizational processes for incorporating the detection of unauthorized security-relevant changes into the incident response capability
  • software, firmware, and information integrity verification tools
  • mechanisms supporting and/or implementing the incorporation of detection of unauthorized security-relevant changes into the incident response capability
Related controls
Official NIST control enhancement

SI-7(8) — Auditing Capability for Significant Events

Upon detection of a potential integrity violation, provide the capability to audit the event and initiate the following actions: [Organization-defined: si-07.08_odp.01].

Official discussion

Organizations select response actions based on types of software, specific software, or information for which there are potential integrity violations.

Organization-defined parameters (3)
si-07.08_odp.01
personnel or rolespersonnel or roles to be alerted upon the detection of a potential integrity violation is/are defined (if selected);
other actionsother actions to be taken upon the detection of a potential integrity violation are defined (if selected);
Assessment objectives and methods
  1. SI-07(08)[01]the capability to audit an event upon the detection of a potential integrity violation is provided;
  2. SI-07(08)[02][Organization-defined: si-07.08_odp.01] is/are initiated upon the detection of a potential integrity violation.

Examine

  • System and information integrity policy
  • system and information integrity procedures
  • procedures addressing software, firmware, and information integrity
  • system design documentation
  • system configuration settings and associated documentation
  • integrity verification tools and associated documentation
  • records of integrity scans
  • incident response records
  • list of security-relevant changes to the system
  • automated tools supporting alerts and notifications if unauthorized security changes are detected
  • system audit records
  • system security plan
  • other relevant documents or records

Interview

  • Organizational personnel responsible for software, firmware, and/or information integrity
  • organizational personnel with information security responsibilities
  • system/network administrators
  • system developer

Test

  • Software, firmware, and information integrity verification tools
  • mechanisms supporting and/or implementing the capability to audit potential integrity violations
  • mechanisms supporting and/or implementing alerts about potential integrity violations
Related controls
Official NIST control enhancement

SI-7(9) — Verify Boot Process

Verify the integrity of the boot process of the following system components: [Organization-defined: system components].

Official discussion

Ensuring the integrity of boot processes is critical to starting system components in known, trustworthy states. Integrity verification mechanisms provide a level of assurance that only trusted code is executed during boot processes.

Organization-defined parameters (1)
system componentssystem components requiring integrity verification of the boot process are defined;
Assessment objectives and methods

the integrity of the boot process of [Organization-defined: system components] is verified.

Examine

  • System and information integrity policy
  • system and information integrity procedures
  • procedures addressing software, firmware, and information integrity
  • system design documentation
  • system configuration settings and associated documentation
  • integrity verification tools and associated documentation
  • documentation
  • records of integrity verification scans
  • system audit records
  • system security plan
  • other relevant documents or records

Interview

  • Organizational personnel responsible for software, firmware, and/or information integrity
  • organizational personnel with information security responsibilities
  • system developer

Test

  • Software, firmware, and information integrity verification tools
  • mechanisms supporting and/or implementing integrity verification of the boot process
Related controls
Official NIST control enhancement

SI-7(10) — Protection of Boot Firmware

Implement the following mechanisms to protect the integrity of boot firmware in [Organization-defined: system components]: [Organization-defined: mechanisms].

Official discussion

Unauthorized modifications to boot firmware may indicate a sophisticated, targeted attack. These types of targeted attacks can result in a permanent denial of service or a persistent malicious code presence. These situations can occur if the firmware is corrupted or if the malicious code is embedded within the firmware. System components can protect the integrity of boot firmware in organizational systems by verifying the integrity and authenticity of all updates to the firmware prior to applying changes to the system component and preventing unauthorized processes from modifying the boot firmware.

Organization-defined parameters (2)
mechanismsmechanisms to be implemented to protect the integrity of boot firmware in system components are defined;
system componentssystem components requiring mechanisms to protect the integrity of boot firmware are defined;
Assessment objectives and methods

[Organization-defined: mechanisms] are implemented to protect the integrity of boot firmware in [Organization-defined: system components].

Examine

  • System and information integrity policy
  • system and information integrity procedures
  • procedures addressing software, firmware, and information integrity
  • system design documentation
  • system configuration settings and associated documentation
  • integrity verification tools and associated documentation
  • records of integrity verification scans
  • system audit records
  • system security plan
  • other relevant documents or records

Interview

  • Organizational personnel responsible for software, firmware, and/or information integrity
  • organizational personnel with information security responsibilities
  • system/network administrators
  • system developer

Test

  • Software, firmware, and information integrity verification tools
  • mechanisms supporting and/or implementing protection of the integrity of boot firmware
  • safeguards implementing protection of the integrity of boot firmware
Related controls
Official NIST control enhancement

SI-7(11) — Confined Environments with Limited Privileges

Withdrawn

This enhancement is marked withdrawn in the official OSCAL catalog. Related-control metadata below may identify where its intent was incorporated.

Official NIST control enhancement

SI-7(12) — Integrity Verification

Require that the integrity of the following user-installed software be verified prior to execution: [Organization-defined: user-installed software].

Official discussion

Organizations verify the integrity of user-installed software prior to execution to reduce the likelihood of executing malicious code or programs that contains errors from unauthorized modifications. Organizations consider the source of the software, ensuring the software and updates come from authorized sources and/or sites, and the practicality of approaches to verifying software integrity, including the availability of trustworthy checksums from software developers and vendors.

Organization-defined parameters (1)
user-installed softwareuser-installed software requiring integrity verification prior to execution is defined;
Assessment objectives and methods

the integrity of [Organization-defined: user-installed software] is verified prior to execution.

Examine

  • System and information integrity policy
  • system and information integrity procedures
  • procedures addressing software, firmware, and information integrity
  • system design documentation
  • system configuration settings and associated documentation
  • integrity verification records
  • system audit records
  • system security plan
  • other relevant documents or records

Interview

  • Organizational personnel responsible for software, firmware, and/or information integrity
  • organizational personnel with information security responsibilities

Test

  • Software, firmware, and information integrity verification tools
  • mechanisms supporting and/or implementing verification of the integrity of user-installed software prior to execution
Related controls
Official NIST control enhancement

SI-7(13) — Code Execution in Protected Environments

Withdrawn

This enhancement is marked withdrawn in the official OSCAL catalog. Related-control metadata below may identify where its intent was incorporated.

Official NIST control enhancement

SI-7(14) — Binary or Machine Executable Code

Withdrawn

This enhancement is marked withdrawn in the official OSCAL catalog. Related-control metadata below may identify where its intent was incorporated.

Official NIST control enhancement

SI-7(15) — Code Authentication

High

Implement cryptographic mechanisms to authenticate the following software or firmware components prior to installation: [Organization-defined: software or firmware components].

Official discussion

Cryptographic authentication includes verifying that software or firmware components have been digitally signed using certificates recognized and approved by organizations. Code signing is an effective method to protect against malicious code. Organizations that employ cryptographic mechanisms also consider cryptographic key management solutions.

Organization-defined parameters (1)
software or firmware componentssoftware or firmware components to be authenticated by cryptographic mechanisms prior to installation are defined;
Assessment objectives and methods

cryptographic mechanisms are implemented to authenticate [Organization-defined: software or firmware components] prior to installation.

Examine

  • System and information integrity policy
  • system and information integrity procedures
  • procedures addressing software, firmware, and information integrity
  • system design documentation
  • system configuration settings and associated documentation
  • cryptographic mechanisms and associated documentation
  • system audit records
  • system security plan
  • other relevant documents or records

Interview

  • Organizational personnel responsible for software, firmware, and/or information integrity
  • organizational personnel with information security responsibilities
  • system/network administrators
  • system developer

Test

  • Cryptographic mechanisms authenticating software and firmware prior to installation
Related controls
Official NIST control enhancement

SI-7(16) — Time Limit on Process Execution Without Supervision

Prohibit processes from executing without supervision for more than [Organization-defined: time period].

Official discussion

Placing a time limit on process execution without supervision is intended to apply to processes for which typical or normal execution periods can be determined and situations in which organizations exceed such periods. Supervision includes timers on operating systems, automated responses, and manual oversight and response when system process anomalies occur.

Organization-defined parameters (1)
time periodthe maximum time period permitted for processes to execute without supervision is defined;
Assessment objectives and methods

processes are prohibited from executing without supervision for more than [Organization-defined: time period].

Examine

  • System and information integrity policy
  • system and information integrity procedures
  • procedures addressing software and information integrity
  • system design documentation
  • system configuration settings and associated documentation
  • system audit records
  • system security plan
  • other relevant documents or records

Interview

  • Organizational personnel responsible for software, firmware, and/or information integrity
  • organizational personnel with information security responsibilities
  • system/network administrators
  • system developer

Test

  • Software, firmware, and information integrity verification tools
  • mechanisms supporting and/or implementing time limits on process execution without supervision
Official NIST control enhancement

SI-7(17) — Runtime Application Self-protection

Implement [Organization-defined: controls] for application self-protection at runtime.

Official discussion

Runtime application self-protection employs runtime instrumentation to detect and block the exploitation of software vulnerabilities by taking advantage of information from the software in execution. Runtime exploit prevention differs from traditional perimeter-based protections such as guards and firewalls which can only detect and block attacks by using network information without contextual awareness. Runtime application self-protection technology can reduce the susceptibility of software to attacks by monitoring its inputs and blocking those inputs that could allow attacks. It can also help protect the runtime environment from unwanted changes and tampering. When a threat is detected, runtime application self-protection technology can prevent exploitation and take other actions (e.g., sending a warning message to the user, terminating the user's session, terminating the application, or sending an alert to organizational personnel). Runtime application self-protection solutions can be deployed in either a monitor or protection mode.

Organization-defined parameters (1)
controlscontrols to be implemented for application self-protection at runtime are defined;
Assessment objectives and methods

[Organization-defined: controls] are implemented for application self-protection at runtime.

Examine

  • System and information integrity policy
  • system and information integrity procedures
  • procedures addressing software and information integrity
  • system design documentation
  • system configuration settings and associated documentation
  • list of known vulnerabilities addressed by runtime instrumentation
  • system security plan
  • other relevant documents or records

Interview

  • Organizational personnel responsible for software, firmware, and/or information integrity
  • organizational personnel with information security responsibilities
  • system/network administrators
  • system developer

Test

  • Software, firmware, and information integrity verification tools
  • mechanisms supporting and/or implementing runtime application self-protection
Related controls
Source record

Authoritative sources