{"data":{"id":"SR-09","name":"Tamper Resistance and Detection","family":"SR","family_name":"Supply Chain Risk Management","withdrawn":false,"description":"Implement a tamper protection program for the system, system component, or system service.","supplemental_guidance":"Anti-tamper technologies, tools, and techniques provide a level of protection for systems, system components, and services against many threats, including reverse engineering, modification, and substitution. Strong identification combined with tamper resistance and/or tamper detection is essential to protecting systems and components during distribution and when in use.","enhancements":[{"id":"SR-09(01)","name":"Multiple Stages of System Development Life Cycle","statement":"Employ anti-tamper technologies, tools, and techniques throughout the system development life cycle.","baselines":["high"]}],"baseline_low":false,"baseline_moderate":false,"baseline_high":true,"nist_800_53":{"rev5":{"id":"SR-09","name":"Tamper Resistance and Detection","description":"Implement a tamper protection program for the system, system component, or system service.","discussion":"Anti-tamper technologies, tools, and techniques provide a level of protection for systems, system components, and services against many threats, including reverse engineering, modification, and substitution. Strong identification combined with tamper resistance and/or tamper detection is essential to protecting systems and components during distribution and when in use.","related_controls":["PE-03","PM-30","SA-15","SI-04","SI-07","SR-03","SR-04","SR-05","SR-10","SR-11"],"baseline_low":false,"baseline_moderate":false,"baseline_high":true,"baseline_privacy":false,"new_in_rev5":true,"changes_from_rev4":"New control family introduced in Rev 5"}},"compliance_mappings":{"iso_27001_2022":[],"iso_27002_2022":["5.21"],"cobit_2019":[],"pci_dss_v4":["9.5"],"nist_csf_2":["ID.RA-09"],"cis_controls_v8":[],"soc2_tsc":[],"finos_ccc":[],"iso_42001_2023":[],"iec_62443":[],"asd_e8":[],"nis2":[],"apra_cps_234":[],"mas_trm":[],"pra_op_resilience":[],"bsi_grundschutz":[],"anssi":["Hygiene.37","Hygiene.42","SecNumCloud.12.2","SecNumCloud.16.1"],"osfi_b13":["B-13.4.1"],"finma_circular":[],"gdpr":["Art.28(1)","Art.28(4)"],"dora":[],"bio2":["5.21"],"rbi_csf":["Annex1.12"],"fisc":[],"lgpd_bcb":[],"hkma_tme1":[],"mlps_2":[],"dnb_good_practice":[],"cra":[],"swift_cscf":[],"uae_ia":["T10"],"ffiec_is":["II.C.14"],"iosco_cyber":["PROT-7"],"nerc_cip":[],"nrc_73_54":[],"tsa_psd":[],"ieee_1686":[],"ferc_cip":[],"doe_c2m2":[],"api_1164":[],"awia":[],"iaea_nss":["Sec 6"],"pci_pts":["A","G","I"],"fips_140":[],"cbest":[],"tiber_eu":[],"pci_hsm":["2","7"],"common_criteria":[],"isae_3402":[],"fca_sysc_13":[],"fda_21_cfr_11":[],"fda_cyber":[],"hitrust_csf":[],"iso_27799":[],"lloyds_ms":[],"naic_ds":[],"nhs_dspt":["NDG-10.4"],"pra_ss1_23":[],"solvency_ii":[],"owasp_masvs_v2":[],"csa_ccm_v4":[],"csa_aicm":[],"ccss_v9":[],"mica":[],"basel_sco60":["SCO60.54"],"bssc":[],"sec_custody_digital":[],"dpdpa":[]},"attack_techniques":[],"metadata":{"last_reviewed":"2026-10-03","review_notes":"2026-10-03: statement, discussion and related controls taken from NIST SP 800-53 Release 5.2.0, which this file lacked.","mapping_status":"complete"},"function":"preventative","used_by_patterns":[]}}