SI-7(12): Integrity Verification
Control Family:
Parent Control:
CSF v1.1 References:
Threats Addressed:
Baselines:
(Not part of any baseline)
Previous Version:
- NIST Special Publication 800-53 Revision 4:
- SI-7(12): Integrity Verification
Control Statement
Require that the integrity of the following user-installed software be verified prior to execution: [Assignment: organization-defined user-installed software].
Supplemental Guidance
Organizations verify the integrity of user-installed software prior to execution to reduce the likelihood of executing malicious code or programs that contains errors from unauthorized modifications. Organizations consider the practicality of approaches to verifying software integrity, including the availability of trustworthy checksums from software developers and vendors.