SI-6—Security Functional Verification
Operational
>Control Description
(A) The information system verifies the correct operation of ⚙organization-defined security functions. (B) The information system performs this verification [Selection (one or more): ⚙organization-defined system transitional states; upon command by user with appropriate privilege; ⚙organization-defined frequency]. (C) The information system notifies ⚙organization-defined personnel or roles of failed security verification tests. (D) The information system [Selection (one or more): shuts the information system down; restarts the information system; ⚙organization-defined alternative action(s)] when anomalies are discovered.
>Supplemental Guidance
Transitional states for information systems include, for example, system start-up, restart, shutdown, and abort. Notifications provided by information systems include, for example, electronic alerts to system administrators, messages to local computer consoles, and/or hardware indications such as lights. Related controls: CA-7, CM-6
Ask AI
Configure your API key to use AI features.