Information Output Filtering

LOW MODERATE HIGH
0 Overlays 3 Related Controls
Graph
Export ▾

Requirements NIST SOURCE

Validate information output from the following software programs and/or applications to ensure that the information is consistent with the expected content: [software programs and/or applications].

Discussion (NIST Supplemental Guidance)

Certain types of attacks, including SQL injections, produce output results that are unexpected or inconsistent with the output results that would be expected from software programs or applications. Information output filtering focuses on detecting extraneous content, preventing such extraneous content from being displayed, and then alerting monitoring tools that anomalous behavior has been discovered.

Implementation Guidance

Engineering Interpretation

Original engineering commentary written for this explorer — not NIST source text and not authoritative guidance.

No engineering interpretation has been authored for SI-15 yet. This section is architected to receive it — see the Requirements and Assessment sections above for the authoritative NIST source content in the meantime.

Assessment

NIST SP 800-53A REV 5.2.0

Assessment Objectives

  1. software programs and/or applications whose information output requires validation are defined;
  2. information output from <SI-15_ODP software programs and/or applications> is validated to ensure that the information is consistent with the expected content.

Examine

[SELECT FROM: System and information integrity policy; system and information integrity procedures; procedures addressing information output filtering; system design documentation; system configuration settings and associated documentation; system audit records; system security plan; other relevant documents or records].

Interview

[SELECT FROM: Organizational personnel responsible for validating information output; organizational personnel with information security responsibilities; system/network administrators; system developer].

Test

[SELECT FROM: Organizational processes for validating information output; automated mechanisms supporting and/or implementing information output validation].

STIGs & CCIs

No STIG checks or CCI mappings are currently loaded for SI-15. This section is architected to display, per product: STIG ID, Finding ID, Severity, Title, Description, Check, Fix, CCI, and NIST control mapping — but nothing is populated here until a real DISA STIG/CCI dataset is ingested.

Learn more about STIG/CCI integration →

Evidence

Potential Evidence — Derived

Categorized from the SP 800-53A "Examine"/"Test" artifact list above by keyword — not an authoritative NIST evidence list.

Policy

  • System and information integrity policy
  • system security plan

Configuration

  • system design documentation
  • system configuration settings and associated documentation

Testing

  • Organizational processes for validating information output
  • automated mechanisms supporting and/or implementing information output validation

Other Records

  • system and information integrity procedures
  • procedures addressing information output filtering
  • system audit records
  • other relevant documents or records