Information Diversity

LOW MODERATE HIGH
0 Overlays 0 Related Controls
Graph
Export ▾

Requirements NIST SOURCE

Discussion (NIST Supplemental Guidance)

Actions taken by a system service or a function are often driven by the information it receives. Corruption, fabrication, modification, or deletion of that information could impact the ability of the service function to properly carry out its intended actions. By having multiple sources of input, the service or function can continue operation if one source is corrupted or no longer available. It is possible that the alternative sources of information may be less precise or less accurate than the primary source of information. But having such sub-optimal information sources may still provide a sufficient level of quality that the essential service or function can be carried out, even in a degraded or debilitated manner.

Implementation Guidance

Engineering Interpretation

Original engineering commentary written for this explorer — not NIST source text and not authoritative guidance.

No engineering interpretation has been authored for SI-22 yet. This section is architected to receive it — see the Requirements and Assessment sections above for the authoritative NIST source content in the meantime.

Assessment

NIST SP 800-53A REV 5.2.0

Assessment Objectives

  1. alternative information sources for essential functions and services are defined;
  2. essential functions and services that require alternative sources of information are defined;
  3. systems or system components that require an alternative information source for the execution of essential functions or services are defined;
  4. <SI-22_ODP[01] alternative information sources> for <SI-22_ODP[02] essential functions and services> are identified;
  5. an alternative information source is used for the execution of essential functions or services on <SI-22_ODP[03] systems or system components> when the primary source of information is corrupted or unavailable.

Examine

[SELECT FROM: System and information integrity policy; system and information integrity procedures; personally identifiable information processing policy; system design documentation; system configuration settings and associated documentation; list of information sources; system security plan; privacy plan; other relevant documents or records].

Interview

[SELECT FROM: Organizational personnel with information security and privacy responsibilities; organizational personnel with systems security engineering responsibilities; system developers].

Test

[SELECT FROM: Automated methods and mechanisms to convert information from an analog to digital medium].

STIGs & CCIs

No STIG checks or CCI mappings are currently loaded for SI-22. This section is architected to display, per product: STIG ID, Finding ID, Severity, Title, Description, Check, Fix, CCI, and NIST control mapping — but nothing is populated here until a real DISA STIG/CCI dataset is ingested.

Learn more about STIG/CCI integration →

Evidence

Potential Evidence — Derived

Categorized from the SP 800-53A "Examine"/"Test" artifact list above by keyword — not an authoritative NIST evidence list.

Policy

  • System and information integrity policy
  • personally identifiable information processing policy
  • system security plan
  • privacy plan

Configuration

  • system design documentation
  • system configuration settings and associated documentation

Testing

  • Automated methods and mechanisms to convert information from an analog to digital medium

Other Records

  • system and information integrity procedures
  • list of information sources
  • other relevant documents or records