SI-3(6)
SI-3(6): Testing / Verification
The organization:
- (a): Tests malicious code protection mechanisms [organization-defined frequency] by introducing a known benign, non-spreading test case into the information system; and
- (b): Verifies that both detection of the test case and associated incident reporting occur.
Supplemental
CIA Levels | |
---|---|
Confidentiality | unknown |
Integrity | unknown |
Availability | unknown |
Overlays |
---|
None |
CSF Categories |
---|
None |