| SI-21 | System and Information Integrity | Information Refresh |
| SI-22 | System and Information Integrity | Information Diversity |
| SI-23 | System and Information Integrity | Information Fragmentation |
| SI-3 | System and Information Integrity | Malicious Code Protection |
| SI-3(1) | System and Information Integrity | Central Management |
| SI-3(10) | System and Information Integrity | Malicious Code Analysis |
| SI-3(2) | System and Information Integrity | Automatic Updates |
| SI-3(3) | System and Information Integrity | Non-privileged Users |
| SI-3(4) | System and Information Integrity | Updates Only by Privileged Users |
| SI-3(5) | System and Information Integrity | Portable Storage Devices |
| SI-3(6) | System and Information Integrity | Testing and Verification |
| SI-3(7) | System and Information Integrity | Nonsignature-based Detection |
| SI-3(8) | System and Information Integrity | Detect Unauthorized Commands |
| SI-3(9) | System and Information Integrity | Authenticate Remote Commands |
| SI-4 | System and Information Integrity | System Monitoring |
| SI-4(1) | System and Information Integrity | System-wide Intrusion Detection System |
| SI-4(10) | System and Information Integrity | Visibility of Encrypted Communications |
| SI-4(11) | System and Information Integrity | Analyze Communications Traffic Anomalies |
| SI-4(12) | System and Information Integrity | Automated Organization-generated Alerts |
| SI-4(13) | System and Information Integrity | Analyze Traffic and Event Patterns |
| SI-4(14) | System and Information Integrity | Wireless Intrusion Detection |
| SI-4(15) | System and Information Integrity | Wireless to Wireline Communications |
| SI-4(16) | System and Information Integrity | Correlate Monitoring Information |
| SI-4(17) | System and Information Integrity | Integrated Situational Awareness |
| SI-4(18) | System and Information Integrity | Analyze Traffic and Covert Exfiltration |
| SI-4(19) | System and Information Integrity | Risk for Individuals |
| SI-4(2) | System and Information Integrity | Automated Tools and Mechanisms for Real-time Analysis |
| SI-4(20) | System and Information Integrity | Privileged Users |
| SI-4(21) | System and Information Integrity | Probationary Periods |
| SI-4(22) | System and Information Integrity | Unauthorized Network Services |
| SI-4(23) | System and Information Integrity | Host-based Devices |
| SI-4(24) | System and Information Integrity | Indicators of Compromise |
| SI-4(25) | System and Information Integrity | Optimize Network Traffic Analysis |
| SI-4(3) | System and Information Integrity | Automated Tool and Mechanism Integration |
| SI-4(4) | System and Information Integrity | Inbound and Outbound Communications Traffic |
| SI-4(5) | System and Information Integrity | System-generated Alerts |
| SI-4(6) | System and Information Integrity | Restrict Non-privileged Users |
| SI-4(7) | System and Information Integrity | Automated Response to Suspicious Events |
| SI-4(8) | System and Information Integrity | Protection of Monitoring Information |
| SI-4(9) | System and Information Integrity | Testing of Monitoring Tools and Mechanisms |
| SI-5 | System and Information Integrity | Security Alerts, Advisories, and Directives |
| SI-5(1) | System and Information Integrity | Automated Alerts and Advisories |
| SI-6 | System and Information Integrity | Security and Privacy Function Verification |
| SI-6(1) | System and Information Integrity | Notification of Failed Security Tests |
| SI-6(2) | System and Information Integrity | Automation Support for Distributed Testing |
| SI-6(3) | System and Information Integrity | Report Verification Results |
| SI-7 | System and Information Integrity | Software, Firmware, and Information Integrity |
| SI-7(1) | System and Information Integrity | Integrity Checks |
| SI-7(10) | System and Information Integrity | Protection of Boot Firmware |
| SI-7(11) | System and Information Integrity | Confined Environments with Limited Privileges |