Policy and Procedures SI-1
System and Information Integrity · Low baseline ✗ Not implemented
Status — program-wide
What references this control
No risks name this control in their Framework field yet.
No policies reference it yet.
Link a risk or policy to this control
Attaching adds SI-1 to the item's Framework field; the ✨ AI button suggests the best match. You can also edit the Framework field on a risk / policy directly.
Source: NIST SP 800-53 Rev.5, System and Information Integrity family NIST SP 800-53 Rev.5. The baseline shows the lowest SP 800-53B baseline (Low / Moderate / High) this control appears in NIST SP 800-53B.
Control guide — plain-English, per NIST SP 800-53
SI-1 (System and Information Integrity policy and procedures) is the written foundation for the whole SI family: a policy that says why integrity matters here and who owns it, plus procedures that spell out how the other SI controls are actually run. It is a documentation control, not a technical one — nothing on the server changes, but every other SI control points back to it. It sits in the Low baseline, so it applies to almost every system.
What good looks like
- Write a System and Information Integrity policy that states its purpose, scope, and how it fits your laws and rules — keep it to a page or two so people actually read it.
- Name the roles and responsibilities: who owns the policy, who approves exceptions, and who does the day-to-day work.
- Write procedures that turn each SI control into steps someone can follow (for example, how flaw remediation, integrity checks, and spam protection are handled).
- Designate an official to manage the policy and procedures — a named person, not ‘the team’.
- Review and update both on a set schedule (for example, yearly) and after big events like a breach, an audit finding, or a major system change.
Framework mapping
- NIST CSF 2.0 — GV.PO-01 — Policy for managing cybersecurity risks is established and communicated
How to move it toward Implemented
- Draft the one-page SI policy and store it with your other control documents, dated and version-numbered.
- Write a short procedures file that lists each SI control you rely on (SI-5, SI-6, SI-7, SI-8, SI-10) and, in a sentence each, how it is run and who runs it.
- Set a calendar reminder for the annual review, and record the reviewer and date at the top of the document.
- Attach the dated policy and procedures as hardening evidence on the asset, naming
SI-1in the Requirement field — that moves it from ‘To assess’ toward ‘Completed’.