File Integrity Monitoring
What is File Integrity Monitoring?
A security control that detects changes to critical system files, configurations, and content by comparing current states against known good baselines.
Terms that appear alongside file integrity monitoring
Each of these is named in at least one of the same controls as file integrity monitoring. The number is how many controls name both.
- integrity 8 shared controls
- integrity monitoring 8 shared controls
- nist 4 shared controls
- baseline 3 shared controls
- malware 3 shared controls
- audit 2 shared controls
- availability 2 shared controls
- anti malware 2 shared controls
Frameworks that govern file integrity monitoring
What the standards actually require on file integrity monitoring
Requirements naming file integrity monitoring across 6 standards, quoted from the control text.
Security Dimension 6 Data Integrity per X.805 Clause 6.6: Data Integrity ensures the correctness or accuracy of data. The data is protected against unauthorized modification + deletion + creation + replication and provides an indication of these unauthorized a...
X805-Dim6-Data-Integrity-Correctness-Accuracy-Unauthorized-Modification-Deletion-Detection · ITU-T X.805 Security Dimension 6 - Data Integrity + Correctness + Accuracy + Unauthorized Modification Prevention + Deletion Detection + Hashing + HMAC + Digital Signatures + Merkle Trees + Blockchain Integrity + File Integrity Monitoring (FIM) →File integrity monitoring or change-detection mechanisms are used on audit logs to ensure that existing log data cannot be changed without generating alerts.
10.3.4 · File integrity or change detection on logs →Detect and respond to unauthorized configuration changes through file integrity monitoring, registry monitoring, change correlation with approved tickets, and alerting on deviations not tied to an approved change record.
SecCM-MONITOR-5 · Unauthorized Change Detection →Apply NIST SP 800-146 Chapter 7 IaaS operational recommendations to every IaaS service consumed. Coverage must include (a) infrastructure-as-code as the canonical provisioning method (no manual console provisioning of production), (b) base image and template h...
NISTSP146-4 · IaaS Operational Recommendations and Workload Hardening →Operate detection and analysis per NIST SP 800-61 Rev 2 Section 3.2 (Detection and Analysis). Tasks include (a) Attack vectors as taxonomy (External/Removable Media + Attrition + Web + Email + Improper Usage + Loss or Theft of Equipment + Other) for categorisa...
NISTSP61-4 · Detection and Analysis: Sources, Triage, Categorisation, Prioritisation →Operate OT configuration + patch + vulnerability + malware protection per NIST SP 800-82 Rev 3 Chapter 6 + Chapter 7. Configuration Management must (a) establish baseline configurations per asset class + version + maintain canonical golden image library, (b) e...
NISTSP82-5 · OT Configuration Management, Patching, Vulnerability Management, and Malware Protection →Questions people ask about file integrity monitoring
What is File Integrity Monitoring?
Why is File Integrity Monitoring important for compliance?
Which compliance frameworks address File Integrity Monitoring?
Where can I learn more about File Integrity Monitoring?
See how File Integrity Monitoring applies across compliance frameworks
Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.