# SI-7(7) — Integration of Detection and Response

- **Control ID:** SI-7(7)
- **Family:** [SI](/md/families/SI.md)
- **Baselines:** moderate, high
- **Enhancement of:** [SI-7](/md/controls/SI-7.md)

## Description

Incorporate the detection of the following unauthorized changes into the organizational incident response capability: \[assignment\].

## Discussion

Integrating detection and response helps to ensure that detected events are tracked, monitored, corrected, and available for historical purposes. Maintaining historical records is important for being able to identify and discern adversary actions over an extended time period and for possible legal actions. Security-relevant changes include unauthorized changes to established configuration settings or the unauthorized elevation of system privileges.

## Implementation guidance

No content available.

## CSF 2.0 subcategories

No content available.

## Related controls

- [AU-2](/md/controls/AU-2.md)
- [AU-6](/md/controls/AU-6.md)
- [IR-4](/md/controls/IR-4.md)
- [IR-5](/md/controls/IR-5.md)
- [SI-4](/md/controls/SI-4.md)

---

Derived from official NIST publications (NIST SP 800-53 Rev 5 and NIST CSF 2.0). nistcontrols.com is not affiliated with NIST.
