SI-6 System and Information Integrity

Security Function Verification

High Risk Moderate Low Cost

SI-6 requires verifying the correct operation of security functions, performing verifications on defined frequencies and transitions, and responding when anomalies are found. EDR that silently dies, audit forwarding that stops, and encryption agents that unload leave ePHI unprotected while dashboards stay green.

Control Objective

Verify on a defined cadence that critical security functions on ePHI systems are operating as intended — and alert/respond when verification fails.

Implementation Guidance

  1. Identify security functions to verify (EDR, disk encryption, audit forwarders, DLP, NAC posture).
  2. Define automated health checks and periodic manual tests.
  3. Verify after patching, reboots, and major changes.
  4. Alert when agents are missing/offline/misconfigured.
  5. Define response SLAs for failed verifications.
  6. Include cloud security controls (logging sinks, conditional access policies).
  7. Retain verification evidence for assessors.
  8. Avoid relying solely on install counts without functional tests.

Real-World Use Cases

How this control shows up in healthcare and HIPAA-covered environments.

Audit forwarder silent failure

SI-6 heartbeat detects EHR audit shipper stopped; restored before an investigation needs the missing logs.

Encryption agent unloaded after update

Verification after patching finds BitLocker/agent issues on clinical laptops; auto-remediation tickets open.

Conditional access policy drift

Periodic verification finds MFA bypass grant left enabled; removed same day.

Best Practices

  • Heartbeats for critical agents.
  • Verify after changes/reboots.
  • Alert and SLA on failures.
  • Functional tests, not only installed=true.
  • Cover cloud control plane.
  • Keep evidence.

Common Gaps & Violations

  • Assuming AV is fine because licensed.
  • No detection of logging outages.
  • Verifications only at annual audit time.
  • Alerts ignored.
  • No post-patch verification.

Required Documentation

  • Security function verification procedure (SI-6)
  • Inventory of functions under verification
  • Monitoring/heartbeat configurations
  • Response SLAs and tickets
  • Evidence samples of checks and fixes

How to Test & Validate

  1. Review heartbeat coverage for EDR/logging on ePHI endpoints/servers.
  2. Sample a failed verification ticket response time.
  3. Confirm post-patch verification exists.
  4. Check cloud control verification.
  5. Validate evidence retention.

Audit Considerations

Silent control failure is a hidden compliance killer. SI-6 shows you know defenses still work between audits.

HIPAA Mapping

How this NIST control supports HIPAA Security Rule expectations.

  • 164.308(a)(8) Evaluation — periodic evaluation includes verifying safeguards function.
  • 164.312(b) Audit Controls — verify audit mechanisms operate.
  • 164.308(a)(5)(ii)(B) Malicious software protection — verify malware defenses are active.
  • 164.306 Reasonable safeguards — safeguards must remain effective over time.

Compliance Tips

  • Page on-call when ePHI audit shipping stops.
  • Include SI-6 checks in change closeout.
  • Report chronic agent offline rates by clinic.

Frequently Asked Questions

Is SI-6 the same as continuous monitoring?

Related; SI-6 specifically verifies security function operation — a key continuous monitoring input.

How often?

Organization-defined — critical functions often continuous/hourly; others daily/weekly.

Do we verify physical locks?

Focus on system security functions; physical checks fall under PE testing procedures.

References & Resources

  • NIST SP 800-53 Rev. 5 — SI-6
  • Related controls: SI-4, SI-7, AU-5, CA-7, CM-3

Need Help Implementing SI-6?

Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.