SI-20 Tainting. Embed data or capabilities in the following systems or system components to determine if organizational data has been exfiltrated or improperly removed from the organization: [organization-defined]
Tainting. Embed data or capabilities in the following systems or system components to determine if organizational data has been exfiltrated or improperly removed from the organization: [organization-defined].
system holds itEvidence a system already holds
none for this control
periodic reviewEvidence produced at each review
- Records of taint detections and the investigations they triggered · Document repository
governing documentDocuments that govern the control
- The defined systems or components in which tainted data or capabilities are embedded · Document repository
- Description of the taint used and how it is designed to be indistinguishable from real data · Document repository
- The detection mechanism that observes taint appearing outside the organisation · Document repository
- Controls preventing the taint from causing operational harm if acted on as real data · Document repository
First move
Common gaps auditors find
- Taint placed only in the store least likely to be exfiltrated, such as a test database
- Taint distinguishable from real records, so an adversary filters it out
- No monitoring for the taint outside the organisation, so embedding it achieves nothing
Do this for your whole sheet
Paste the rows you run your controls from and get this mapping for every control at once, with the periodic-review ones flagged and a first move per row. No account for the first run.
Build my evidence sheetSI-19 De-identification. Remove the following elements of personally identifiable information from datasets: [organization-defined] ; and Evaluate [organization-defined] for effectiveness of de-identification · SI-21 Information Refresh. Refresh [organization-defined] at [organization-defined] or generate the information on demand and delete the information when no longer needed