Under active development Content is continuously updated and improved
Home / Frameworks / FedRAMP Rev 5 / SI — System and Information Integrity

SI System and Information Integrity

35 controls in the System and Information Integrity family

SI-1Policy and Procedures
LI-SaaS
LOW
MODERATE
HIGH
SI-2Flaw Remediation
LI-SaaS
LOW
MODERATE
HIGH
SI-2 (02)Flaw Remediation | Automated Flaw Remediation Status
MODERATE
HIGH
SI-2 (03)Flaw Remediation | Time to Remediate Flaws and Benchmarks for Corrective Actions
MODERATE
HIGH
SI-3Malicious Code Protection
LI-SaaS
LOW
MODERATE
HIGH
SI-4System Monitoring
LI-SaaS
LOW
MODERATE
HIGH
SI-4 (01)System Monitoring | System-wide Intrusion Detection System
MODERATE
HIGH
SI-4 (02)System Monitoring | Automated Tools and Mechanisms for Real-time Analysis
MODERATE
HIGH
SI-4 (04)System Monitoring | Inbound and Outbound Communications Traffic
MODERATE
HIGH
SI-4 (05)System Monitoring | System-generated Alerts
MODERATE
HIGH
SI-4 (10)System Monitoring | Visibility of Encrypted Communications
HIGH
SI-4 (11)System Monitoring | Analyze Communications Traffic Anomalies
HIGH
SI-4 (12)System Monitoring | Automated Organization-generated Alerts
HIGH
SI-4 (14)System Monitoring | Wireless Intrusion Detection
HIGH
SI-4 (16)System Monitoring | Correlate Monitoring Information
MODERATE
HIGH
SI-4 (18)System Monitoring | Analyze Traffic and Covert Exfiltration
MODERATE
HIGH
SI-4 (19)System Monitoring | Risk for Individuals
HIGH
SI-4 (20)System Monitoring | Privileged Users
HIGH
SI-4 (22)System Monitoring | Unauthorized Network Services
HIGH
SI-4 (23)System Monitoring | Host-based Devices
MODERATE
HIGH
SI-5Security Alerts, Advisories, and Directives
LI-SaaS
LOW
MODERATE
HIGH
SI-5 (01)Security Alerts, Advisories, and Directives | Automated Alerts and Advisories
HIGH
SI-6Security and Privacy Function Verification
MODERATE
HIGH
SI-7Software, Firmware, and Information Integrity
MODERATE
HIGH
SI-7 (01)Software, Firmware, and Information Integrity | Integrity Checks
MODERATE
HIGH
SI-7 (02)Software, Firmware, and Information Integrity | Automated Notifications of Integrity Violations
HIGH
SI-7 (05)Software, Firmware, and Information Integrity | Automated Response to Integrity Violations
HIGH
SI-7 (07)Software, Firmware, and Information Integrity | Integration of Detection and Response
MODERATE
HIGH
SI-7 (15)Software, Firmware, and Information Integrity | Code Authentication
HIGH
SI-8Spam Protection
MODERATE
HIGH
SI-8 (02)Spam Protection | Automatic Updates
MODERATE
HIGH
SI-10Information Input Validation
MODERATE
HIGH
SI-11Error Handling
MODERATE
HIGH
SI-12Information Management and Retention
LI-SaaS
LOW
MODERATE
HIGH
SI-16Memory Protection
MODERATE
HIGH