FedRAMP Controls / SI

SI-16 Memory Protection

Family SI
Baselines moderate
Mapped KSIs 2

Control statement

Implement the following controls to protect the system memory from unauthorized code execution: {{ insert: param, si-16_odp }}.

Parameter placeholders {{ insert: param, … }} reference FedRAMP-set values in the resolved profile. Full parameter map is preserved in the catalog database.

Covered by these Key Security Indicators

KSITitleCategory
KSI-CNA-02Attack Surface
_Persistently_ ensure _machine-based_ _information resources_ have a minimal attack surface and that lateral movement is minimized if compromised.
Cloud Native Architecture
KSI-PIY-04CISA Secure By Design
_Persistently_ review the effectiveness of building security and privacy considerations into the Software Development Lifecycle and aligning with CISA Secure By Design principles.
Policy and Inventory