FedRAMP Controls / SI
SI-7 Software, Firmware, and Information Integrity
Family SI
Baselines moderate
Mapped KSIs 1
Control statement
a. Employ integrity verification tools to detect unauthorized changes to the following software, firmware, and information: {{ insert: param, si-7_prm_1 }} ; and
b. Take the following actions when unauthorized changes to the software, firmware, and information are detected: {{ insert: param, si-7_prm_2 }}. Parameter placeholders {{ insert: param, … }} reference FedRAMP-set values in the resolved profile. Full parameter map is
preserved in the catalog database.
Covered by these Key Security Indicators
| KSI | Title | Category |
|---|---|---|
| KSI-SVC-05 | Resource Integrity Use cryptographic methods to validate the integrity of machine-based information resources. | Service Configuration |