| SI-1 | System and Information Integrity | Policy and Procedures |
| SI-10 | System and Information Integrity | Information Input Validation |
| SI-10(1) | System and Information Integrity | Manual Override Capability |
| SI-10(2) | System and Information Integrity | Review and Resolve Errors |
| SI-10(3) | System and Information Integrity | Predictable Behavior |
| SI-10(4) | System and Information Integrity | Timing Interactions |
| SI-10(5) | System and Information Integrity | Restrict Inputs to Trusted Sources and Approved Formats |
| SI-10(6) | System and Information Integrity | Injection Prevention |
| SI-11 | System and Information Integrity | Error Handling |
| SI-12 | System and Information Integrity | Information Management and Retention |
| SI-12(1) | System and Information Integrity | Limit Personally Identifiable Information Elements |
| SI-12(2) | System and Information Integrity | Minimize Personally Identifiable Information in Testing, Training, and Research |
| SI-12(3) | System and Information Integrity | Information Disposal |
| SI-13 | System and Information Integrity | Predictable Failure Prevention |
| SI-13(1) | System and Information Integrity | Transferring Component Responsibilities |
| SI-13(2) | System and Information Integrity | Time Limit on Process Execution Without Supervision |
| SI-13(3) | System and Information Integrity | Manual Transfer Between Components |
| SI-13(4) | System and Information Integrity | Standby Component Installation and Notification |
| SI-13(5) | System and Information Integrity | Failover Capability |
| SI-14 | System and Information Integrity | Non-persistence |
| SI-14(1) | System and Information Integrity | Refresh from Trusted Sources |
| SI-14(2) | System and Information Integrity | Non-persistent Information |
| SI-14(3) | System and Information Integrity | Non-persistent Connectivity |
| SI-15 | System and Information Integrity | Information Output Filtering |
| SI-16 | System and Information Integrity | Memory Protection |
| SI-17 | System and Information Integrity | Fail-safe Procedures |
| SI-18 | System and Information Integrity | Personally Identifiable Information Quality Operations |
| SI-18(1) | System and Information Integrity | Automation Support |
| SI-18(2) | System and Information Integrity | Data Tags |
| SI-18(3) | System and Information Integrity | Collection |
| SI-18(4) | System and Information Integrity | Individual Requests |
| SI-18(5) | System and Information Integrity | Notice of Correction or Deletion |
| SI-19 | System and Information Integrity | De-identification |
| SI-19(1) | System and Information Integrity | Collection |
| SI-19(2) | System and Information Integrity | Archiving |
| SI-19(3) | System and Information Integrity | Release |
| SI-19(4) | System and Information Integrity | Removal, Masking, Encryption, Hashing, or Replacement of Direct Identifiers |
| SI-19(5) | System and Information Integrity | Statistical Disclosure Control |
| SI-19(6) | System and Information Integrity | Differential Privacy |
| SI-19(7) | System and Information Integrity | Validated Algorithms and Software |
| SI-19(8) | System and Information Integrity | Motivated Intruder |
| SI-2 | System and Information Integrity | Flaw Remediation |
| SI-2(1) | System and Information Integrity | Central Management |
| SI-2(2) | System and Information Integrity | Automated Flaw Remediation Status |
| SI-2(3) | System and Information Integrity | Time to Remediate Flaws and Benchmarks for Corrective Actions |
| SI-2(4) | System and Information Integrity | Automated Patch Management Tools |
| SI-2(5) | System and Information Integrity | Automatic Software and Firmware Updates |
| SI-2(6) | System and Information Integrity | Removal of Previous Versions of Software and Firmware |
| SI-2(7) | System and Information Integrity | Root Cause Analysis |
| SI-20 | System and Information Integrity | Tainting |