NIST 800-53 Rev 5

424 controls available

SI-7(7)moderatehigh

Integration of Detection and Response

System and Information Integrity

Control Statement

Incorporate the detection of the following unauthorized changes into the organizational incident response capability: {{ insert: param, si-07.07_odp }}.

Discussion

Integrating detection and response helps to ensure that detected events are tracked, monitored, corrected, and available for historical purposes. Maintaining historical records is important for being able to identify and discern adversary actions over an extended time period and for possible legal actions. Security-relevant changes include unauthorized changes to established configuration settings or the unauthorized elevation of system privileges.

Framework
NIST SP 800-53 Rev 5
Family
System and Information Integrity
Baselines
moderate, high

Related Frameworks

3 paths across 2 frameworks
SCF1 mapping
END-06.2Endpoint Detection & Response (EDR)
1.00
  • Secure Controls Framework · 2026.2 · scf_strm · equivalent
CCI2 mappings
CCI-002719
1.00
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-002720
1.00
  • DISA · 2025-01-23 · disa_cci_list · equivalent

Related STIGs

8 STIGs reach this control through 46 CCIs. Expand a row to see the responsible NICE and O*NET roles.

Operating System - Mainframe

2 STIGs
Mainframe Product Security Requirements Guide
32024-12-055 of 193 findings match
Mainframe Product Security Requirements Guide
V3R42025-09-105 of 194 findings match

Network Device

2 STIGs

Endpoint Security Management

2 STIGs

Uncategorized

2 STIGs
Mainframe Product Security Requirements Guide
V3R52026-05-235 of 194 findings match