Tamper Detection
What is Tamper Detection?
Mechanisms that detect and alert on physical tampering with devices, enclosures, or seals protecting sensitive equipment or data.
Terms that appear alongside tamper detection
Each of these is named in at least one of the same controls as tamper detection. The number is how many controls name both.
- integrity 11 shared controls
- nist 6 shared controls
- authentication 6 shared controls
- iec 62443 5 shared controls
- secure boot 4 shared controls
- audit 4 shared controls
- vulnerability 3 shared controls
- penetration testing 3 shared controls
Frameworks that govern tamper detection
What the standards actually require on tamper detection
Requirements naming tamper detection across 6 standards, quoted from the control text.
UR E27 requires equipment manufacturers to deliver CBS with logging + forensic readiness capabilities aligned with IEC 62443-4-2 CR 2.8-2.12 (Auditable events) + FR 6 (Timely Response to Events).
IACS-UR-E27-Logging-Forensics-EventCapture · IACS UR E27 - Equipment Logging + Forensic Readiness + Event Capture + Tamper Detection →Detect and respond to tampering of OT devices, cabinets, and network equipment through seals, sensors, alarms, and inspection procedures.
OT-PHYS-3 · Tamper Detection and Response →A change- and tamper-detection mechanism is deployed for payment pages to alert personnel to unauthorized modifications to HTTP headers and contents of payment pages as received by the consumer browser.
11.6.1 · Payment page change and tamper detection →Section 5.1 establishes electronic access account management capabilities required of IEDs. Per public IEEE 1686 + IEEE Std abstract + vendor capability statements (full IEEE text NOT reproduced): individual user accounts with unique identification (5.1) + no...
IEEE1686-Section5.1-AccessControl-Accounts-Roles-Password-Session-Remote · IEEE 1686 Section 5.1 - Electronic Access Account Management + Roles + Password + Failed Login + Session + Remote Access + Personnel →GLI-33 audit + logging + security + change + resilience. SIGNIFICANT EVENT LOGGING: every regulatorily significant event must be logged with timestamp (regulator-time-source-synced typically via NTP + Stratum-1) + actor + action + outcome + correlated session/...
GLI33-Audit-Logging-InfoSec-ChangeControl · GLI-33 Audit, Significant Event Logging, Information Security, Change Control, Resilience →Implement policies and procedures to protect ePHI from improper alteration or destruction. NIST recommends integrity controls including checksums, signed records, and tamper detection.
164.312(c)(1) · Integrity (Standard) →Questions people ask about tamper detection
What is Tamper Detection?
Why is Tamper Detection important for compliance?
Which compliance frameworks address Tamper Detection?
Where can I learn more about Tamper Detection?
See how Tamper Detection applies across compliance frameworks
Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.