{
  "node_id": "data-integrity-detecting-responding-ransomware",
  "title": "NIST SPECIAL PUBLICATION 1800-26 Data Integrity: Detecting and Responding to Ransomware and Other Destructive Events",
  "domain": "Cybersecurity",
  "version": "1.0.0",
  "last_updated": "2020-12-31",
  "bluf": "This guide focuses on data integrity: the property that data has not been altered in an unauthorized manner, covering data in storage, during processing, and while in transit. Destructive malware, ransomware, malicious insider activity, and even honest mistakes all necessitate that organizations detect and respond to an event that impacts data integrity in a timely fashion. Attacks against an organization’s data can compromise emails, employee records, financial records, and customer information-impacting business operations, revenue, and reputation. Examples of data integrity attacks include unauthorized insertion, deletion, or modification of data.\n\nThis NIST Cybersecurity Practice Guide demonstrates how organizations can develop and implement appropriate actions during a detected data integrity cybersecurity event. The National Cybersecurity Center of Excellence (NCCoE) at NIST built a laboratory environment to explore methods to effectively detect and respond to a data integrity event in various IT enterprise environments. The guide demonstrates a solution that incorporates multiple systems working in concert to detect an ongoing data integrity cybersecurity event and provides guidance on how to respond to the detected event, enabling organizations to have the necessary tools to act during a data integrity attack.",
  "paywall": {
    "status": "LOCKED",
    "unlock_cost_usd": "0.01",
    "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
  },
  "crosswalks": {
    "_available_keys": [
      "nist_framework",
      "iso_standard",
      "industry_mapping"
    ],
    "_note": "Full crosswalk values included in vault response"
  },
  "dependencies": [
    "nist-cybersecurity-framework-2-0",
    "nist-sp-800-53-r5",
    "nist-sp-800-61r2-incident-handling",
    "nist-sp-1800-25-data-integrity",
    "nist-sp-1800-11-data-integrity",
    "cisa-ms-isac-ransomware-guide"
  ],
  "primary_citations_count": 9
}