SI-22 Information Diversity
a. Identify the following alternative sources of information for si-22_odp.02: si-22_odp.01 ; and
b. Use an alternative information source for the execution of essential functions or services on si-22_odp.03 when the primary source of information is corrupted or unavailable.
Parameter ID | Definition |
---|---|
si-22_odp.01 | alternative information sources |
si-22_odp.02 | essential functions and services |
si-22_odp.03 | systems or system components |
Baselines
- L
- M
- H
- P
Guidance
Actions taken by a system service or a function are often driven by the information it receives. Corruption, fabrication, modification, or deletion of that information could impact the ability of the service function to properly carry out its intended actions. By having multiple sources of input, the service or function can continue operation if one source is corrupted or no longer available. It is possible that the alternative sources of information may be less precise or less accurate than the primary source of information. But having such sub-optimal information sources may still provide a sufficient level of quality that the essential service or function can be carried out, even in a degraded or debilitated manner.
References 1
- SP 800-160-2 Ross RS, Pillitteri VY, Graubart R, Bodeau D, McQuaid R (2019) Developing Cyber Resilient Systems: A Systems Security Engineering Approach. (National Institute of Standards and Technology, Gaithersburg, MD), NIST Special Publication (SP) 800-160, Vol. 2.