{"data":{"id":"SI-23","name":"Information Fragmentation","family":"SI","family_name":"System and Information Integrity","withdrawn":false,"description":"Based on [Assignment: organization-defined circumstances]:\na. Fragment the following information: [Assignment: organization-defined information]; and\nb. Distribute the fragmented information across the following systems or system components: [Assignment: organization-defined systems or system components].","supplemental_guidance":"One objective of the advanced persistent threat is to exfiltrate valuable information. Once exfiltrated, there is generally no way for the organization to recover the lost information. Therefore, organizations may consider dividing the information into disparate elements and distributing those elements across multiple systems or system components and locations. Such actions will increase the adversary’s work factor to capture and exfiltrate the desired information and, in so doing, increase the probability of detection. The fragmentation of information impacts the organization’s ability to access the information in a timely manner. The extent of the fragmentation is dictated by the impact or classification level (and value) of the information, threat intelligence information received, and whether data tainting is used (i.e., data tainting-derived information about the exfiltration of some information could result in the fragmentation of the remaining information).","enhancements":[],"baseline_low":false,"baseline_moderate":false,"baseline_high":false,"nist_800_53":{"rev5":{"id":"SI-23","name":"Information Fragmentation","description":"Based on [Assignment: organization-defined circumstances]:\na. Fragment the following information: [Assignment: organization-defined information]; and\nb. Distribute the fragmented information across the following systems or system components: [Assignment: organization-defined systems or system components].","discussion":"One objective of the advanced persistent threat is to exfiltrate valuable information. Once exfiltrated, there is generally no way for the organization to recover the lost information. Therefore, organizations may consider dividing the information into disparate elements and distributing those elements across multiple systems or system components and locations. Such actions will increase the adversary’s work factor to capture and exfiltrate the desired information and, in so doing, increase the probability of detection. The fragmentation of information impacts the organization’s ability to access the information in a timely manner. The extent of the fragmentation is dictated by the impact or classification level (and value) of the information, threat intelligence information received, and whether data tainting is used (i.e., data tainting-derived information about the exfiltration of some information could result in the fragmentation of the remaining information).","related_controls":[],"baseline_low":null,"baseline_moderate":null,"baseline_high":null,"baseline_privacy":null,"new_in_rev5":true,"changes_from_rev4":"New control in Rev 5."}},"compliance_mappings":{"iso_27001_2022":[],"iso_27002_2022":[],"cobit_2019":[],"pci_dss_v4":[],"nist_csf_2":[],"cis_controls_v8":[],"soc2_tsc":[],"finos_ccc":[],"iso_42001_2023":[],"iec_62443":[],"asd_e8":[],"nis2":[],"apra_cps_234":[],"mas_trm":[],"pra_op_resilience":[],"bsi_grundschutz":[],"anssi":[],"osfi_b13":[],"finma_circular":[],"gdpr":[],"dora":[],"bio2":[],"rbi_csf":["Annex1.4"],"fisc":[],"lgpd_bcb":[],"hkma_tme1":[],"mlps_2":[],"dnb_good_practice":[],"cra":[],"swift_cscf":[],"nerc_cip":[],"nrc_73_54":[],"tsa_psd":[],"ieee_1686":[],"ferc_cip":[],"doe_c2m2":[],"api_1164":[],"awia":[],"iaea_nss":[],"pci_pts":[],"fips_140":[],"cbest":[],"tiber_eu":[],"pci_hsm":[],"common_criteria":[],"isae_3402":[],"fca_sysc_13":[],"fda_21_cfr_11":[],"fda_cyber":[],"hitrust_csf":[],"iso_27799":[],"lloyds_ms":[],"naic_ds":[],"nhs_dspt":[],"pra_ss1_23":[],"solvency_ii":[],"owasp_masvs_v2":[],"csa_ccm_v4":[],"csa_aicm":[],"ccss_v9":[],"mica":[],"basel_sco60":[],"bssc":[],"sec_custody_digital":[],"dpdpa":[]},"attack_techniques":[{"id":"T1070","name":"Indicator Removal","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Information fragmentation distributes log and audit data across multiple independent stores, ensuring adversaries who remove indicators from one location cannot eliminate all forensic evidence."},{"id":"T1072","name":"Software Deployment Tools","tactics":["execution","lateral-movement"],"mapping_type":"mitigates","mapping_rationale":"Fragmenting deployment configurations across multiple independent systems prevents adversaries from using a single compromised software deployment tool to access complete infrastructure data."},{"id":"T1119","name":"Automated Collection","tactics":["collection"],"mapping_type":"mitigates","mapping_rationale":"Information fragmentation defeats automated collection by distributing data across multiple systems and formats, ensuring automated harvesting tools cannot assemble complete datasets from any single source."},{"id":"T1565","name":"Data Manipulation","tactics":["impact"],"mapping_type":"mitigates","mapping_rationale":"Distributing data across fragmented stores limits the impact of data manipulation, since adversaries must compromise multiple independent systems to affect a complete dataset."},{"id":"T1070.001","name":"Clear Windows Event Logs","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Fragmenting Windows Event Logs across multiple collection points ensures that clearing logs on any single system does not eliminate the complete audit trail of adversary activity."},{"id":"T1070.002","name":"Clear Linux or Mac System Logs","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Distributing Linux and macOS system logs across fragmented collection infrastructure ensures clearing logs on one system preserves evidence in independent log aggregation points."},{"id":"T1565.001","name":"Stored Data Manipulation","tactics":["impact"],"mapping_type":"mitigates","mapping_rationale":"Fragmenting stored data across independent systems limits the impact of data manipulation, since adversaries must modify matching records in multiple separate stores to achieve consistent falsification."}],"metadata":{"last_reviewed":"2026-02-13","review_notes":"","mapping_status":"pending"},"function":"preventative","used_by_patterns":[]}}