Identify the following alternative sources of information for [organization-defined]: [organization-defined] ;
Scanned 9/3/2026
Install to Claude Code
npx -y skills add CyberStrikeus/CyberStrike --skill SI-22_information-diversity --agent claude-codeInstalls into .claude/skills of the current project.
Are you the author of SI 22 Information Diversity?
Add the live security badge to your README — it updates automatically with every re-scan.
[](https://www.skillsdirectory.com/skills/cyberstrikeus-si-22-information-diversity)More formats (shields.io, HTML) on the badges page.
---
name: "SI-22_information-diversity"
description: "Identify the following alternative sources of information for [organization-defined]: [organization-defined] ;"
category: "input-validation"
version: "5.2.0"
author: "cyberstrike-official"
tags:
- nist
- sp800-53
- rev5
- si-22
- si
tech_stack:
- aws
- azure
- gcp
- linux
- windows
cwe_ids:
- CWE-20
chains_with: []
prerequisites: []
severity_boost: {}
---
# SI-22 Information Diversity
## High-Level Description
**Family:** System and Information Integrity (SI)
**Framework:** NIST SP 800-53 Rev 5
Actions taken by a system service or a function are often driven by the information it receives. Corruption, fabrication, modification, or deletion of that information could impact the ability of the service function to properly carry out its intended actions. By having multiple sources of input, the service or function can continue operation if one source is corrupted or no longer available. It is possible that the alternative sources of information may be less precise or less accurate than the primary source of information. But having such sub-optimal information sources may still provide a sufficient level of quality that the essential service or function can be carried out, even in a degraded or debilitated manner.
## What to Check
- [ ] Verify SI-22 Information Diversity is documented in SSP
- [ ] Validate all 2 control requirements are implemented
- [ ] Confirm control is operating effectively
- [ ] Review evidence of continuous monitoring for SI-22
## How to Test
### Step 1: Review Documentation
Examine the System Security Plan (SSP) and related artifacts for SI-22 implementation details. Verify the organization has documented how this control is satisfied.
### Step 2: Validate Implementation
```
# For cloud environments, use cloud-audit-mcp tools
# For on-premises, review system configurations directly
# Example: Check if account management policies exist
grep -r "account.management\|access.control" /etc/security/ 2>/dev/null
```
### Step 3: Test Operating Effectiveness
Verify the control is actively functioning, not just documented. Check logs, configurations, and operational evidence.
## Tools
| Tool | Purpose | Usage |
| --------------- | -------------------------- | ------------------------------ |
| cloud-audit-mcp | Check integrity monitoring | `cloud_audit_monitoring` |
| AWS CLI | Review GuardDuty/Inspector | `aws guardduty list-detectors` |
## Remediation Guide
### Control Statement
Identify the following alternative sources of information for [organization-defined]: [organization-defined] ; and
Use an alternative information source for the execution of essential functions or services on [organization-defined] when the primary source of information is corrupted or unavailable.
### Implementation Guidance
Actions taken by a system service or a function are often driven by the information it receives. Corruption, fabrication, modification, or deletion of that information could impact the ability of the service function to properly carry out its intended actions. By having multiple sources of input, the service or function can continue operation if one source is corrupted or no longer available. It is possible that the alternative sources of information may be less precise or less accurate than the primary source of information. But having such sub-optimal information sources may still provide a sufficient level of quality that the essential service or function can be carried out, even in a degraded or debilitated manner.
## Risk Assessment
| Finding | Severity | Impact |
| ------------------------------------------- | -------- | ------------------------------------------- |
| SI-22 Information Diversity not implemented | High | System and Information Integrity |
| SI-22 partially implemented | Medium | Incomplete System and Information Integrity |
## CWE Categories
| CWE ID | Title |
| ------ | ------------------------- |
| CWE-20 | Improper Input Validation |
## References
- [NIST SP 800-53 Rev 5 - SI-22](https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=si-22)
- [NIST SP 800-53A Rev 5 (Assessment Procedures)](https://csrc.nist.gov/pubs/sp/800/53/a/r5/final)
- [NIST SP 800-53 Rev 5 Full Catalog](https://csrc.nist.gov/pubs/sp/800/53/r5/upd1/final)
## Checklist
- [ ] Control documented in SSP
- [ ] Implementation evidence collected
- [ ] Operating effectiveness validated
- [ ] Continuous monitoring in place
- [ ] Related controls (none) reviewed
Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.
No comments yet. Be the first to comment!