Information Integrity
Requirement to protect information from unauthorized or accidental alteration, erasure, or damage.
What Counts
- Integrity validation for stored and transmitted information
- Controls that prevent unauthorized modification or deletion
- Monitoring and audit trails for material changes
- Tested recovery from accidental corruption or erasure
What Does Not Count
- Availability controls that do not protect against alteration
- Accuracy goals without integrity safeguards
- Backups that are never tested for reliable recovery
Implementing Frameworks
| Framework | Scope | Status | Provisions |
|---|---|---|---|
| ISO/IEC 27001:2022 | International | active | 1 |