# SR-09 Tamper Resistance and Detection

NIST SP 800-53 control. Family: SR Supply Chain Risk Management. Function: preventative. Baselines: high. Mapping licence: CC BY-SA 4.0.

Statement: Implement a tamper protection program for the system, system component, or system service.
Guidance: Anti-tamper technologies, tools, and techniques provide a level of protection for systems, system components, and services against many threats, including reverse engineering, modification, and substitution. Strong identification combined with tamper resistance and/or tamper detection is essential to protecting systems and components during distribution and when in use.

## Enhancements (1)
- SR-09(01) Multiple Stages of System Development Life Cycle. Baselines: high
Each enhancement's statement: /api/v1/controls/SR-09?fields=enhancements

## Clauses by framework (16 frameworks)
- iso_27002_2022: 5.21
- pci_dss_v4: 9.5
- nist_csf_2: ID.RA-09. OSA's own, not in NIST's crosswalk: ID.RA-09
- anssi: Hygiene.37, Hygiene.42, SecNumCloud.12.2, SecNumCloud.16.1
- osfi_b13: B-13.4.1
- gdpr: Art.28(1), Art.28(4)
- bio2: 5.21
- rbi_csf: Annex1.12
- uae_ia: T10
- ffiec_is: II.C.14
- iosco_cyber: PROT-7
- iaea_nss: Sec 6
- pci_pts: A, G, I
- pci_hsm: 2, 7
- nhs_dspt: NDG-10.4
- basel_sco60: SCO60.54
OSA's mapping for nist_csf_2 takes NIST's published crosswalk as its base. A clause not marked as OSA's own is in that crosswalk.

## More
- This control as JSON, with guidance and ATT&CK techniques: /api/v1/controls/SR-09
- Clauses only: /api/v1/controls/SR-09?fields=mappings
- Page for people: /controls/sr-09/
- Found an error? Open an issue at https://github.com/opensecurityarchitecture/osa-data/issues with the id, what OSA says and what the source says.
