36 MAC Pt. 1, R. 17.1

System and Information Integrity

Year: 2026Length: 348 wordsOfficial source

Cite as 36 Miss. Admin. Code Pt. 1, R. 17.1

System and Information Integrity A. Each agency must identify, report, and correct system flaws in a timely manner. B. Each agency must monitor, control, and protect communications. 1. Establish and maintain a documented vulnerability management and remediation process for enterprise assets. Review and update documentation annually, or when significant enterprise changes occur that could impact this Safeguard. 2. Remediate detected vulnerabilities in software through processes and tooling on a monthly, or more frequent basis, based on the remediation process. C. Each agency must provide protection from malware at designated locations within organizational systems. 1. Deploy and maintain anti-malware software on all enterprise assets, where appropriate and/or supported. Further, agencies should deploy anti-malware scanning at the network level to include, at a minimum, the network external boundary. D. Each agency must monitor system security alerts and advisories and take action in response. 1. Centralize security event alerting across enterprise assets for log correlation and analysis. Best practice implementation requires the use of a SIEM, which includes vendor-defined event correlation alerts. A log analytics platform configured with security-relevant correlation alerts also satisfies this Safeguard. E. Each agency must update malware protection mechanisms when new releases are available. 1. Configure automatic updates for anti-malware signature files on all enterprise assets. F. Each agency must perform periodic scans of organizational systems on a weekly basis at minimum, and real-time scans of files from external sources as files are downloaded, opened, or executed. 1. Configure anti-malware software to automatically scan removable media. G. Each agency must monitor agency systems, including inbound and outbound communications traffic, to detect attacks and indicators of potential attacks. 1. Deploy a host-based intrusion detection solution on enterprise assets, where appropriate and/or supported. 2. Deploy a network intrusion detection solution on enterprise assets, where appropriate. Example implementations include the use of a Network Intrusion Detection System (NIDS) or equivalent cloud service provider (CSP) service. H. Each agency must identify unauthorized use of agency systems via aggregating user logins and other system events and reviewing them on a consistent basis or immediately upon identifying a potential or realized security event.
36 MAC Pt. 1, R. 17.1: System and Information Integrity | Justis AI