Predictable Failure Prevention
LOW MODERATE HIGHRequirements NIST SOURCE
Requirement Context
This element is part of SI-13 — Predictable Failure Prevention. See the Assessment section below for the related SP 800-53A examine/interview/test procedures. No engineering interpretation has been authored for this control yet.
Requirement Context
This element is part of SI-13 — Predictable Failure Prevention. See the Assessment section below for the related SP 800-53A examine/interview/test procedures. No engineering interpretation has been authored for this control yet.
Discussion (NIST Supplemental Guidance)
While MTTF is primarily a reliability issue, predictable failure prevention is intended to address potential failures of system components that provide security capabilities. Failure rates reflect installation-specific consideration rather than the industry-average. Organizations define the criteria for the substitution of system components based on the MTTF value with consideration for the potential harm from component failures. The transfer of responsibilities between active and standby components does not compromise safety, operational readiness, or security capabilities. The preservation of system state variables is also critical to help ensure a successful transfer process. Standby components remain available at all times except for maintenance issues or recovery failures in progress.
Enhancements NIST SOURCE
SI-13(1) Transferring Component Responsibilities LOW MODERATE HIGH
Take system components out of service by transferring component responsibilities to substitute components no later than [fraction or percentage] of mean time to failure.
Discussion
Transferring primary system component responsibilities to other substitute components prior to primary component failure is important to reduce the risk of degraded or debilitated mission or business functions. Making such transfers based on a percentage of mean time to failure allows organizations to be proactive based on their risk tolerance. However, the premature replacement of system components can result in the increased cost of system operations.
SI-13(2) Time Limit on Process Execution Without Supervision WITHDRAWN
Withdrawn. Incorporated into SI-7(16).
SI-13(3) Manual Transfer Between Components LOW MODERATE HIGH
Manually initiate transfers between active and standby system components when the use of the active component reaches [percentage] of the mean time to failure.
Discussion
For example, if the MTTF for a system component is 100 days and the MTTF percentage defined by the organization is 90 percent, the manual transfer would occur after 90 days.
SI-13(4) Standby Component Installation and Notification LOW MODERATE HIGH
If system component failures are detected:
- (a) Ensure that the standby components are successfully and transparently installed within [time period] ; and
- (b) [one of: activate; automatically shut down the system; ].
Discussion
Automatic or manual transfer of components from standby to active mode can occur upon the detection of component failures.
SI-13(5) Failover Capability LOW MODERATE HIGH
Provide [one of: real-time; near real-time][failover capability] for the system.
Discussion
Failover refers to the automatic switchover to an alternate system upon the failure of the primary system. Failover capability includes incorporating mirrored system operations at alternate processing sites or periodic data mirroring at regular intervals defined by the recovery time periods of organizations.
Implementation Guidance
Original engineering commentary written for this explorer — not NIST source text and not authoritative guidance.
No engineering interpretation has been authored for SI-13 yet. This section is architected to receive it — see the Requirements and Assessment sections above for the authoritative NIST source content in the meantime.
Assessment
Assessment Objectives
- system components for which mean time to failure (MTTF) should be determined are defined;
- mean time to failure (MTTF) substitution criteria to be used as a means to exchange active and standby components are defined;
- mean time to failure (MTTF) is determined for <SI-13_ODP[01] system components> in specific environments of operation;
- substitute system components and a means to exchange active and standby components are provided in accordance with <SI-13_ODP[02] mean time to failure (MTTF) substitution criteria>.
Examine
[SELECT FROM: System and information integrity policy; system and information integrity procedures; procedures addressing predictable failure prevention; system design documentation; system configuration settings and associated documentation; list of MTTF substitution criteria; system audit records; system security plan; other relevant documents or records].
Interview
[SELECT FROM: Organizational personnel responsible for MTTF determinations and activities; organizational personnel with information security responsibilities; system/network administrators; organizational personnel with contingency planning responsibilities].
Test
[SELECT FROM: Organizational processes for managing MTTF].
Overlays
STIGs & CCIs
No STIG checks or CCI mappings are currently loaded for SI-13. This section is architected to display, per product: STIG ID, Finding ID, Severity, Title, Description, Check, Fix, CCI, and NIST control mapping — but nothing is populated here until a real DISA STIG/CCI dataset is ingested.
Learn more about STIG/CCI integration →Evidence
Categorized from the SP 800-53A "Examine"/"Test" artifact list above by keyword — not an authoritative NIST evidence list.
Policy
- System and information integrity policy
- system security plan
Configuration
- system design documentation
- system configuration settings and associated documentation
Testing
- Organizational processes for managing MTTF
Other Records
- system and information integrity procedures
- procedures addressing predictable failure prevention
- list of MTTF substitution criteria
- system audit records
- other relevant documents or records