STIGhubSTIGhub
STIGsRMF ControlsCompare
STIGhub— A free STIG search and compliance tool·STIGs updated 3 days ago
Powered by Pylon·Privacy·Terms·© 2026 Beacon Cloud Solutions, Inc.
← All Controls

SI-23

System and Information IntegrityRev 5organization

Information Fragmentation

Control Statement

Based on [Assignment: circumstances]:

Supplemental Guidance

One objective of the advanced persistent threat is to exfiltrate valuable information. Once exfiltrated, there is generally no way for the organization to recover the lost information. Therefore, organizations may consider dividing the information into disparate elements and distributing those elements across multiple systems or system components and locations. Such actions will increase the adversary’s work factor to capture and exfiltrate the desired information and, in so doing, increase the probability of detection. The fragmentation of information impacts the organization’s ability to access the information in a timely manner. The extent of the fragmentation is dictated by the impact or classification level (and value) of the information, threat intelligence information received, and whether data tainting is used (i.e., data tainting-derived information about the exfiltration of some information could result in the fragmentation of the remaining information).

CCI Identifiers (6)

CCI-005050Based on organization-defined circumstances, fragment the following information.CCI-005051Defines the information for fragmentation.CCI-005052Defines the circumstances for fragmenting organization-defined information.CCI-005053Based on organization-defined circumstances, distribute the fragmented information across the following systems or system components.CCI-005054Defines the systems or system components used to distribute fragmented information.CCI-005055Defines the circumstances for distributing fragmented information across organization-defined systems or system components.

Linked STIG Checks (0)

No STIG checks reference this control.