| SI-7(12) | System and Information Integrity | Integrity Verification |
| SI-7(13) | System and Information Integrity | Code Execution in Protected Environments |
| SI-7(14) | System and Information Integrity | Binary or Machine Executable Code |
| SI-7(15) | System and Information Integrity | Code Authentication |
| SI-7(16) | System and Information Integrity | Time Limit on Process Execution Without Supervision |
| SI-7(17) | System and Information Integrity | Runtime Application Self-protection |
| SI-7(2) | System and Information Integrity | Automated Notifications of Integrity Violations |
| SI-7(3) | System and Information Integrity | Centrally Managed Integrity Tools |
| SI-7(4) | System and Information Integrity | Tamper-evident Packaging |
| SI-7(5) | System and Information Integrity | Automated Response to Integrity Violations |
| SI-7(6) | System and Information Integrity | Cryptographic Protection |
| SI-7(7) | System and Information Integrity | Integration of Detection and Response |
| SI-7(8) | System and Information Integrity | Auditing Capability for Significant Events |
| SI-7(9) | System and Information Integrity | Verify Boot Process |
| SI-8 | System and Information Integrity | Spam Protection |
| SI-8(1) | System and Information Integrity | Central Management |
| SI-8(2) | System and Information Integrity | Automatic Updates |
| SI-8(3) | System and Information Integrity | Continuous Learning Capability |
| SI-9 | System and Information Integrity | Information Input Restrictions |
| SR-1 | Supply Chain Risk Management | Policy and Procedures |
| SR-10 | Supply Chain Risk Management | Inspection of Systems or Components |
| SR-11 | Supply Chain Risk Management | Component Authenticity |
| SR-11(1) | Supply Chain Risk Management | Anti-counterfeit Training |
| SR-11(2) | Supply Chain Risk Management | Configuration Control for Component Service and Repair |
| SR-11(3) | Supply Chain Risk Management | Anti-counterfeit Scanning |
| SR-12 | Supply Chain Risk Management | Component Disposal |
| SR-2 | Supply Chain Risk Management | Supply Chain Risk Management Plan |
| SR-2(1) | Supply Chain Risk Management | Establish SCRM Team |
| SR-3 | Supply Chain Risk Management | Supply Chain Controls and Processes |
| SR-3(1) | Supply Chain Risk Management | Diverse Supply Base |
| SR-3(2) | Supply Chain Risk Management | Limitation of Harm |
| SR-3(3) | Supply Chain Risk Management | Sub-tier Flow Down |
| SR-4 | Supply Chain Risk Management | Provenance |
| SR-4(1) | Supply Chain Risk Management | Identity |
| SR-4(2) | Supply Chain Risk Management | Track and Trace |
| SR-4(3) | Supply Chain Risk Management | Validate as Genuine and Not Altered |
| SR-4(4) | Supply Chain Risk Management | Supply Chain Integrity — Pedigree |
| SR-5 | Supply Chain Risk Management | Acquisition Strategies, Tools, and Methods |
| SR-5(1) | Supply Chain Risk Management | Adequate Supply |
| SR-5(2) | Supply Chain Risk Management | Assessments Prior to Selection, Acceptance, Modification, or Update |
| SR-6 | Supply Chain Risk Management | Supplier Assessments and Reviews |
| SR-6(1) | Supply Chain Risk Management | Testing and Analysis |
| SR-7 | Supply Chain Risk Management | Supply Chain Operations Security |
| SR-8 | Supply Chain Risk Management | Notification Agreements |
| SR-9 | Supply Chain Risk Management | Tamper Resistance and Detection |
| SR-9(1) | Supply Chain Risk Management | Multiple Stages of System Development Life Cycle |