System and Information Integrity CMMC Family Description
System and Information Integrity focuses on the organization's ability to identify, report, and correct information and information system flaws in a timely manner. This family consists of practices with requirements to provide protection from malicious code at appropriate locations within organizational information systems and update those protection mechanisms when new releases are available. Furthermore, this family includes performing periodic scans of the information system and real-time scans of files from external sources as files are downloaded, opened, or executed in support of system integrity.
Cybertorch/Quzara Offerings for System and Information Integrity
By implementing the Cybertorch™ managed service, you satisfy 12 of the 13 CMMC SI control requirements (including maturity levels 4 and 5) based on all of the built-in functionality that comes with this managed service.
This Cybertorch™ functionality includes:
Performing periodic and real-time scans of files
Monitoring system security alerts and taking action in response to those alerts
Providing protection against malware and updating malware protection mechanisms when new releases are available.
Monitoring inbound and outbound communication traffic to detect indicators of attacks
Employing spam protection
Identifying unauthorized use of organization's systems, Implementing email forgery protections
Utilizing a sandbox to detect & block potentially malicious emails, using threat indicator information relevant to the protected systems for threat hunting
Analyzing system behavior to detect and mitigate commands and scripts that indicate malicious actions
Monitoring individuals and systems on an ongoing basis for anomalous/suspicious behavior