Under active development Content is continuously updated and improved

SI-6Security Functional Verification

Operational

>Control Description

(A) The information system verifies the correct operation of organization-defined security functions. (B) The information system performs this verification [Selection (one or more): organization-defined system transitional states; upon command by user with appropriate privilege; organization-defined frequency]. (C) The information system notifies organization-defined personnel or roles of failed security verification tests. (D) The information system [Selection (one or more): shuts the information system down; restarts the information system; organization-defined alternative action(s)] when anomalies are discovered.

>Supplemental Guidance

Transitional states for information systems include, for example, system start-up, restart, shutdown, and abort. Notifications provided by information systems include, for example, electronic alerts to system administrators, messages to local computer consoles, and/or hardware indications such as lights. Related controls: CA-7, CM-6

Ask AI

Configure your API key to use AI features.