SI-13 Predictable Failure Prevention

System and Information Integrity

Description

Determine mean time to failure (MTTF) for the following system components in specific environments of operation: [Assignment: organization-defined parameters] ; and Provide substitute system components and a means to exchange active and standby components in accordance with the following criteria: [Assignment: organization-defined parameters].

Supplemental Guidance

While MTTF is primarily a reliability issue, predictable failure prevention is intended to address potential failures of system components that provide security capabilities. Failure rates reflect installation-specific consideration rather than the industry-average. Organizations define the criteria for the substitution of system components based on the MTTF value with consideration for the potential harm from component failures. The transfer of responsibilities between active and standby components does not compromise safety, operational readiness, or security capabilities. The preservation of system state variables is also critical to help ensure a successful transfer process. Standby components remain available at all times except for maintenance issues or recovery failures in progress.

Changes from Rev 4

No significant title changes from Rev 4.

Compliance Mappings

COBIT 2019

BAI04

MAS TRM

7

BSI IT-Grundschutz

DER.4

ANSSI

SecNumCloud.13.3SecNumCloud.18.1

FINMA Circular 2023/1

IV.A(28)IV.A(29)IV.E(89)

EU DORA

Art.7(1)Art.9(2)

RBI CSF

ITGRCA.29

FISC Security Guidelines

FISC.O13FISC.O2

HKMA TM-E-1

TME1.5.2TME1.5.3

DNB Good Practice

DNB.11.4

EU CRA

CRA.I.2h

CBB TM

TM-5

Qatar NIA

BC

CBUAE

CR-13

CBE CSF

OVM-2

SA JS2

JS2-7.5

CBN CSF

Part3.7

BoG CISD

CISD-BCM

BCBS 239

Principle 5

EBA ICT Guidelines

3.5(a)

SEBI CSCRF

PR.MA

BOT Cyber Resilience

Ch4.2

Solvency II

EIOPA-ICT-4.8

FCA SYSC 13

SYSC 13.7.2SYSC 13.8.2

FDA Cybersecurity Guidance

SA-6

MiCA

Art.68(5)Art.62(5)