Doc:NIST SP 800-53Ar1 FPD Appendix F/Enhanced/SI
From FISMApedia
|
SP 800-53Ar1 FPD Assessment Procedure Catalog, with SP 800-53r3 Security Controls
SYSTEM AND INFORMATION INTEGRITY
SI-1
| FAMILY: SYSTEM AND INFORMATION INTEGRITY | CLASS: OPERATIONAL |
| SECURITY CONTROL |
|---|
|
SI-1 SYSTEM AND INFORMATION INTEGRITY POLICY AND PROCEDURES
|
| ASSESSMENT PROCEDURE | ||
|---|---|---|
| SI-1 | SYSTEM AND INFORMATION INTEGRITY POLICY AND PROCEDURES | |
| SI-1.1 | ASSESSMENT OBJECTIVE:
| |
| SI-1.2 | ASSESSMENT OBJECTIVE:
| |
SI-2
| FAMILY: SYSTEM AND INFORMATION INTEGRITY | CLASS: OPERATIONAL |
| SECURITY CONTROL |
|---|
|
SI-2 FLAW REMEDIATION
|
| ASSESSMENT PROCEDURE | ||
|---|---|---|
| SI-2 | FLAW REMEDIATION | |
| SI-2.1 | ASSESSMENT OBJECTIVE:
| |
| SECURITY CONTROL ENHANCEMENT |
|---|
|
| SI-2(1) | FLAW REMEDIATION | |
| SI-2(1).1 | ASSESSMENT OBJECTIVE:
|
| SECURITY CONTROL ENHANCEMENT |
|---|
|
| SI-2(2) | FLAW REMEDIATION | |
| SI-2(2).1 | ASSESSMENT OBJECTIVE:
|
| SECURITY CONTROL ENHANCEMENT |
|---|
|
| SI-2(3) | FLAW REMEDIATION | |
| SI-2(3).1 | ASSESSMENT OBJECTIVE:
|
| SECURITY CONTROL ENHANCEMENT |
|---|
|
| SI-2(4) | FLAW REMEDIATION | |
| SI-2(4).1 | ASSESSMENT OBJECTIVE:
|
SI-3
| FAMILY: SYSTEM AND INFORMATION INTEGRITY | CLASS: OPERATIONAL |
| SECURITY CONTROL |
|---|
|
SI-3 MALICIOUS CODE PROTECTION
|
| ASSESSMENT PROCEDURE | ||
|---|---|---|
| SI-3 | MALICIOUS CODE PROTECTION | |
| SI-3.1 | ASSESSMENT OBJECTIVE:
| |
| SECURITY CONTROL ENHANCEMENT |
|---|
|
| SI-3(1) | MALICIOUS CODE PROTECTION | |
| SI-3(1).1 | ASSESSMENT OBJECTIVE:
|
| SECURITY CONTROL ENHANCEMENT |
|---|
|
| SI-3(2) | MALICIOUS CODE PROTECTION | |
| SI-3(2).1 | ASSESSMENT OBJECTIVE:
|
| SECURITY CONTROL ENHANCEMENT |
|---|
|
| SI-3(3) | MALICIOUS CODE PROTECTION | |
| SI-3(3).1 | ASSESSMENT OBJECTIVE:
|
| SECURITY CONTROL ENHANCEMENT |
|---|
|
| SI-3(4) | MALICIOUS CODE PROTECTION | |
| SI-3(4).1 | ASSESSMENT OBJECTIVE:
|
| SECURITY CONTROL ENHANCEMENT |
|---|
|
| SI-3(5) | MALICIOUS CODE PROTECTION | |
| SI-3(5).1 | ASSESSMENT OBJECTIVE:
|
| SECURITY CONTROL ENHANCEMENT |
|---|
|
| SI-3(6) | MALICIOUS CODE PROTECTION | |
| SI-3(6).1 | ASSESSMENT OBJECTIVE:
|
SI-4
| FAMILY: SYSTEM AND INFORMATION INTEGRITY | CLASS: OPERATIONAL |
| SECURITY CONTROL |
|---|
|
SI-4 INFORMATION SYSTEM MONITORING
|
| ASSESSMENT PROCEDURE | ||
|---|---|---|
| SI-4 | INFORMATION SYSTEM MONITORING | |
| SI-4.1 | ASSESSMENT OBJECTIVE:
| |
| SECURITY CONTROL ENHANCEMENT |
|---|
|
| SI-4(1) | INFORMATION SYSTEM MONITORING | |
| SI-4(1).1 | ASSESSMENT OBJECTIVE:
|
| SECURITY CONTROL ENHANCEMENT |
|---|
|
| SI-4(2) | INFORMATION SYSTEM MONITORING | |
| SI-4(2).1 | ASSESSMENT OBJECTIVE:
|
| SECURITY CONTROL ENHANCEMENT |
|---|
|
| SI-4(3) | INFORMATION SYSTEM MONITORING | |
| SI-4(3).1 | ASSESSMENT OBJECTIVE:
|
| SECURITY CONTROL ENHANCEMENT |
|---|
|
| SI-4(4) | INFORMATION SYSTEM MONITORING | |
| SI-4(4).1 | ASSESSMENT OBJECTIVE:
|
| SECURITY CONTROL ENHANCEMENT |
|---|
|
| SI-4(5) | INFORMATION SYSTEM MONITORING | |
| SI-4(5).1 | ASSESSMENT OBJECTIVE:
|
| SECURITY CONTROL ENHANCEMENT |
|---|
|
| SI-4(6) | INFORMATION SYSTEM MONITORING | |
| SI-4(6).1 | ASSESSMENT OBJECTIVE:
|
| SECURITY CONTROL ENHANCEMENT |
|---|
|
| SI-4(7) | INFORMATION SYSTEM MONITORING | |
| SI-4(7).1 | ASSESSMENT OBJECTIVE:
|
| SECURITY CONTROL ENHANCEMENT |
|---|
|
| SI-4(8) | INFORMATION SYSTEM MONITORING | |
| SI-4(8).1 | ASSESSMENT OBJECTIVE:
|
| SECURITY CONTROL ENHANCEMENT |
|---|
|
| SI-4(9) | INFORMATION SYSTEM MONITORING | |
| SI-4(9).1 | ASSESSMENT OBJECTIVE:
|
| SECURITY CONTROL ENHANCEMENT |
|---|
|
| SI-4(10) | INFORMATION SYSTEM MONITORING | |
| SI-4(10).1 | ASSESSMENT OBJECTIVE:
|
| SECURITY CONTROL ENHANCEMENT |
|---|
|
| SI-4(11) | INFORMATION SYSTEM MONITORING | |
| SI-4(11).1 | ASSESSMENT OBJECTIVE:
|
| SECURITY CONTROL ENHANCEMENT |
|---|
|
| SI-4(12) | INFORMATION SYSTEM MONITORING | |
| SI-4(12).1 | ASSESSMENT OBJECTIVE:
|
| SECURITY CONTROL ENHANCEMENT |
|---|
|
| SI-4(13) | INFORMATION SYSTEM MONITORING | |
| SI-4(13).1 | ASSESSMENT OBJECTIVE:
|
| SECURITY CONTROL ENHANCEMENT |
|---|
|
| SI-4(14) | INFORMATION SYSTEM MONITORING | |
| SI-4(14).1 | ASSESSMENT OBJECTIVE:
|
| SECURITY CONTROL ENHANCEMENT |
|---|
|
| SI-4(15) | INFORMATION SYSTEM MONITORING | |
| SI-4(15).1 | ASSESSMENT OBJECTIVE:
|
| SECURITY CONTROL ENHANCEMENT |
|---|
|
| SI-4(16) | INFORMATION SYSTEM MONITORING | |
| SI-4(16).1 | ASSESSMENT OBJECTIVE:
|
| SECURITY CONTROL ENHANCEMENT |
|---|
|
| SI-4(17) | INFORMATION SYSTEM MONITORING | |
| SI-4(17).1 | ASSESSMENT OBJECTIVE:
|
SI-5
| FAMILY: SYSTEM AND INFORMATION INTEGRITY | CLASS: OPERATIONAL |
| SECURITY CONTROL |
|---|
|
SI-5 SECURITY ALERTS, ADVISORIES, AND DIRECTIVES
|
| ASSESSMENT PROCEDURE | ||
|---|---|---|
| SI-5 | SECURITY ALERTS, ADVISORIES, AND DIRECTIVES | |
| SI-5.1 | ASSESSMENT OBJECTIVE:
| |
| SECURITY CONTROL ENHANCEMENT |
|---|
|
| SI-5(1) | SECURITY ALERTS, ADVISORIES, AND DIRECTIVES | |
| SI-5(1).1 | ASSESSMENT OBJECTIVE:
|
SI-6
| FAMILY: SYSTEM AND INFORMATION INTEGRITY | CLASS: OPERATIONAL |
| SECURITY CONTROL |
|---|
|
SI-6 SECURITY FUNCTIONALITY VERIFICATION
|
| ASSESSMENT PROCEDURE | ||
|---|---|---|
| SI-6 | SECURITY FUNCTIONALITY VERIFICATION | |
| SI-6.1 | ASSESSMENT OBJECTIVE:
| |
| SECURITY CONTROL ENHANCEMENT |
|---|
|
| SI-6(1) | SECURITY FUNCTIONALITY VERIFICATION | |
| SI-6(1).1 | ASSESSMENT OBJECTIVE:
|
| SECURITY CONTROL ENHANCEMENT |
|---|
|
| SI-6(2) | SECURITY FUNCTIONALITY VERIFICATION | |
| SI-6(2).1 | ASSESSMENT OBJECTIVE:
|
| SECURITY CONTROL ENHANCEMENT |
|---|
|
| SI-6(3) | SECURITY FUNCTIONALITY VERIFICATION | |
| SI-6(3).1 | ASSESSMENT OBJECTIVE:
|
SI-7
| FAMILY: SYSTEM AND INFORMATION INTEGRITY | CLASS: OPERATIONAL |
| SECURITY CONTROL |
|---|
|
SI-7 SOFTWARE AND INFORMATION INTEGRITY
|
| ASSESSMENT PROCEDURE | ||
|---|---|---|
| SI-7 | SOFTWARE AND INFORMATION INTEGRITY | |
| SI-7.1 | ASSESSMENT OBJECTIVE:
| |
| SECURITY CONTROL ENHANCEMENT |
|---|
|
| SI-7(1) | SOFTWARE AND INFORMATION INTEGRITY | |
| SI-7(1).1 | ASSESSMENT OBJECTIVE:
|
| SECURITY CONTROL ENHANCEMENT |
|---|
|
| SI-7(2) | SOFTWARE AND INFORMATION INTEGRITY | |
| SI-7(2).1 | ASSESSMENT OBJECTIVE:
|
| SECURITY CONTROL ENHANCEMENT |
|---|
|
| SI-7(3) | SOFTWARE AND INFORMATION INTEGRITY | |
| SI-7(3).1 | ASSESSMENT OBJECTIVE:
|
| SECURITY CONTROL ENHANCEMENT |
|---|
|
| SI-7(4) | SOFTWARE AND INFORMATION INTEGRITY | |
| SI-7(4).1 | ASSESSMENT OBJECTIVE:
|
SI-8
| FAMILY: SYSTEM AND INFORMATION INTEGRITY | CLASS: OPERATIONAL |
| SECURITY CONTROL |
|---|
|
SI-8 SPAM PROTECTION
|
| ASSESSMENT PROCEDURE | ||
|---|---|---|
| SI-8 | SPAM PROTECTION | |
| SI-8.1 | ASSESSMENT OBJECTIVE:
| |
| SECURITY CONTROL ENHANCEMENT |
|---|
|
| SI-8(1) | SPAM PROTECTION | |
| SI-8(1).1 | ASSESSMENT OBJECTIVE:
|
| SECURITY CONTROL ENHANCEMENT |
|---|
|
| SI-8(2) | SPAM PROTECTION | |
| SI-8(2).1 | ASSESSMENT OBJECTIVE:
|
SI-9
| FAMILY: SYSTEM AND INFORMATION INTEGRITY | CLASS: OPERATIONAL |
| SECURITY CONTROL |
|---|
|
SI-9 INFORMATION INPUT RESTRICTIONS
|
| ASSESSMENT PROCEDURE | ||
|---|---|---|
| SI-9 | INFORMATION INPUT RESTRICTIONS | |
| SI-9.1 | ASSESSMENT OBJECTIVE:
| |
SI-10
| FAMILY: SYSTEM AND INFORMATION INTEGRITY | CLASS: OPERATIONAL |
| SECURITY CONTROL |
|---|
|
SI-10 INFORMATION INPUT VALIDATION
|
| ASSESSMENT PROCEDURE | ||
|---|---|---|
| SI-10 | INFORMATION INPUT VALIDATION | |
| SI-10.1 | ASSESSMENT OBJECTIVE:
| |
SI-11
| FAMILY: SYSTEM AND INFORMATION INTEGRITY | CLASS: OPERATIONAL |
| SECURITY CONTROL |
|---|
|
SI-11 ERROR HANDLING
|
| ASSESSMENT PROCEDURE | ||
|---|---|---|
| SI-11 | ERROR HANDLING | |
| SI-11.1 | ASSESSMENT OBJECTIVE:
| |
SI-12
| FAMILY: SYSTEM AND INFORMATION INTEGRITY | CLASS: OPERATIONAL |
| SECURITY CONTROL |
|---|
|
SI-12 INFORMATION OUTPUT HANDLING AND RETENTION
|
| ASSESSMENT PROCEDURE | ||
|---|---|---|
| SI-12 | INFORMATION OUTPUT HANDLING AND RETENTION | |
| SI-12.1 | ASSESSMENT OBJECTIVE:
| |
SI-13
| FAMILY: SYSTEM AND INFORMATION INTEGRITY | CLASS: OPERATIONAL |
| SECURITY CONTROL |
|---|
|
SI-13 PREDICTABLE FAILURE PREVENTION
|
| ASSESSMENT PROCEDURE | ||
|---|---|---|
| SI-13 | PREDICTABLE FAILURE PREVENTION | |
| SI-13.1 | ASSESSMENT OBJECTIVE:
| |
| SECURITY CONTROL ENHANCEMENT |
|---|
|
| SI-13(1) | PREDICTABLE FAILURE PREVENTION | |
| SI-13(1).1 | ASSESSMENT OBJECTIVE:
|
| SECURITY CONTROL ENHANCEMENT |
|---|
|
| SI-13(2) | PREDICTABLE FAILURE PREVENTION | |
| SI-13(2).1 | ASSESSMENT OBJECTIVE:
|
| SECURITY CONTROL ENHANCEMENT |
|---|
|
| SI-13(3) | PREDICTABLE FAILURE PREVENTION | |
| SI-13(3).1 | ASSESSMENT OBJECTIVE:
|
| SECURITY CONTROL ENHANCEMENT |
|---|
|
| SI-13(4) | PREDICTABLE FAILURE PREVENTION | |
| SI-13(4).1 | ASSESSMENT OBJECTIVE:
|
del.icio.us
digg
Facebook
Newsvine
reddit
Slashdot