System and Information Integrity Policy and Procedures
Internal Use
System and Information Integrity Policy and Procedures
Dispel
Document Control
| Item | Details |
|---|---|
| Version | 1.0 |
| Cadence | Annual |
| Policy Owner | Chief Information Security Officer |
| Approved By | Chief Executive Officer |
| DCF References | DCF-1, DCF-12, DCF-13, DCF-18, DCF-19, DCF-20, DCF-21, DCF-22, DCF-23, DCF-24, DCF-28, DCF-29, DCF-30, DCF-32, DCF-33, DCF-35, DCF-36, DCF-38, DCF-39, DCF-40, DCF-41, DCF-43, DCF-44, DCF-45, DCF-47, DCF-48, DCF-49, DCF-51, DCF-52, DCF-55, DCF-56, DCF-57, DCF-58, DCF-60, DCF-72, DCF-73, DCF-74, DCF-80, DCF-81, DCF-83, DCF-84, DCF-96, DCF-99, DCF-100, DCF-134 |
1. PURPOSE AND SCOPE
1.1 Purpose
The purpose of this policy and procedures document is to define how Dispel maintains the integrity of its systems and information, including flaw remediation, malicious code protection, system monitoring, integrity checking, and related safeguards.
1.2 Scope
This policy applies to:
- Dispel systems and services in scope for the security and compliance program, including the Dispel Zero Trust Engine.
- Supporting processes and controls required to maintain the integrity of systems and information.
1.3 Regulatory and Framework Alignment
| # | Framework / Standard | Relevant Control IDs | Alignment Notes |
|---|---|---|---|
| 1 | SOC 2 | CC6.1, CC6.6, CC7.2, CC7.3, CC7.4 | Logical access, system monitoring, and vulnerability and incident management related to integrity. |
| 2 | ISO/IEC 27001 | A.5.12, A.5.13, A.5.23, A.8.11 | Requirements for data integrity, protection of system functions, and technical vulnerability management. |
| 3 | NIST SP 800-53 | SI-1, SI-2, SI-2(2), SI-2(3), SI-3, SI-4, SI-4(1), SI-4(2), SI-4(4), SI-4(5), SI-4(10), SI-4(11), SI-4(12), SI-4(14), SI-4(16), SI-4(18), SI-4(19), SI-4(20), SI-4(22), SI-4(23), SI-5, SI-5(1), SI-6, SI-7, SI-7(1), SI-7(2), SI-7(5), SI-7(7), SI-7(15), SI-8, SI-8(2), SI-10, SI-11, SI-12, SI-16 | Flaw remediation, malicious code protection, system monitoring, integrity protection, and related safeguards. |
| 4 | IEC 62443 | 62443-2-1.4.3 | Integrity and monitoring requirements for industrial control systems. |
| 5 | HIPAA | 164.308(a)(1), 164.308(a)(5), 164.308(a)(6), 164.308(a)(7), 164.312(c), 164.312(e) | Integrity, malware protection, monitoring, and transmission security for systems handling ePHI. |
2. POLICY STATEMENTS
2.1 Management Commitment
Management Commitment Statement
Senior Management at Dispel is dedicated to the protection of our information assets, industrial control systems, and Protected Health Information (PHI). We assume full accountability for the effectiveness of our security program, ensuring it is integrated into all business processes and aligned with our strategic goals. To maintain compliance with ISO 27001, IEC 62443, HIPAA, and NIST 800-53, we formally commit to:
- Resource Provisioning: Providing the necessary financial, technical, and human resources to sustain a robust security posture.
- Risk-Based Governance: Approving security policies and overseeing a continuous risk management process that prioritizes both data privacy and operational safety.
- Operational Resilience: Supporting the security of industrial automation and control systems (IACS) to ensure safety and reliability.
- Continuous Oversight: Conducting regular management reviews to evaluate program performance, audit results, and opportunities for improvement.
2.2 Primary Policy Statement
Dispel SHALL implement and maintain controls to protect the integrity of systems and information, detect and remediate flaws, and monitor for malicious or anomalous activity.
2.3 Secondary Policy Statement
- System flaws SHALL be identified, assessed, and remediated in a timely manner.
- Malicious code protection and integrity monitoring capabilities SHALL be deployed and maintained.
3. REQUIREMENTS
3.1 Flaw Remediation
Objective: Identify, assess, and remediate system flaws.
Mandatory Activities:
- Dispel SHALL have processes to receive, analyze, and act on information about system vulnerabilities and flaws.
- Flaws SHALL be prioritized based on risk and remediated according to defined timelines.
- Where immediate remediation is not possible, compensating controls SHALL be considered and documented.
Required Outputs:
- Flaw remediation procedures.
- Records of identified flaws, risk ratings, and remediation status.
Security Controls: NIST SP 800-53 SI-2.
3.2 Malicious Code Protection and System Monitoring
Objective: Protect systems from malicious code and monitor for anomalous activity.
Mandatory Activities:
- Malicious code protection mechanisms (e.g., anti-malware, endpoint protection) SHALL be deployed on appropriate systems.
- System and network monitoring capabilities (e.g., IDS/IPS, EDR, log analysis) SHALL be used to detect anomalous or suspicious activity.
- Alerts from malicious code and monitoring tools SHALL be integrated into incident response processes.
Required Outputs:
- Configuration and deployment records for malicious code protection and monitoring tools.
- Alerts and investigation records.
Security Controls: NIST SP 800-53 SI-3, SI-4.
3.3 Information and Software Integrity
Objective: Ensure the integrity of information and software components.
Mandatory Activities:
- Integrity-checking mechanisms (e.g., checksums, digital signatures, file integrity monitoring) SHALL be used for critical software and configuration items.
- Detected integrity violations SHALL be investigated and treated as potential security incidents.
- Integrity controls SHALL be protected from unauthorized modification or disabling.
Required Outputs:
- Integrity monitoring configurations and reports.
- Records of detected integrity issues and responses.
Security Controls: NIST SP 800-53 SI-7, SI-8, SI-10, SI-11, SI-12.
4. ROLES AND RESPONSIBILITIES
4.1 Policy Owner
Responsibilities:
- Owns this System and Information Integrity Policy and Procedures.
- Ensures integration with Vulnerability Management, Logging and Monitoring, and Incident Response policies.
4.2 Security Officer / Security Operations
Responsibilities:
- Oversee flaw remediation, malicious code protection, and monitoring programs.
- Analyze alerts and coordinate with Incident Response.
4.3 System Owners / Administrators
Responsibilities:
- Implement and maintain integrity-related controls on systems they manage.
- Coordinate flaw remediation and integrity monitoring activities.
5. PROCEDURES
5.1 System and Information Integrity Lifecycle (High-Level)
| Step | Action | Responsible Party | Timeframe |
|---|---|---|---|
| 1 | Identify and assess system flaws and integrity risks. | Security Officer, System Owners | Ongoing |
| 2 | Implement and update malicious code and monitoring solutions. | Security Operations, Administrators | Ongoing |
| 3 | Monitor for anomalies and integrity violations; investigate alerts. | Security Operations | Ongoing |
| 4 | Remediate identified issues and update controls as needed. | System Owners, Security Officer | As required |
| 5 | Review integrity and flaw remediation metrics and adjust processes. | Policy Owner, Security Officer | At least annually |
6. MONITORING AND COMPLIANCE
Compliance with this policy SHALL be monitored through:
- Vulnerability and integrity assessments.
- Reviews of monitoring and alert handling.
- Periodic audits of integrity-related controls.
7. EXCEPTIONS AND WAIVERS
Exceptions to this policy SHALL follow the documented exception management process and require appropriate approvals.
8. DEFINITIONS
System Flaw: A weakness in hardware, firmware, or software that may be exploited or cause unexpected behavior.
Malicious Code: Software or code designed to perform unauthorized or harmful actions.
9. REFERENCES
- Vulnerability Management Policy.
- Logging and Monitoring Policy.
- NIST SP 800-53, SI family.
10. DOCUMENT HISTORY
| Version | Date | Author | Changes |
|---|---|---|---|
| 1.1 | Predates version control | Ethan Schmertzler | Aligned System and Information Integrity Policy and Procedures to POLICY_TEMPLATE and updated control mappings. |
| 1.0 | Predates version control | Ethan Schmertzler | Initial System and Information Integrity Policy and Procedures. |
11. APPROVAL SIGNATURES
| Role | Name | Signature | Date |
|---|---|---|---|
| Policy Owner | |||
| Security Officer | |||
| Senior Management Representative |