Security Dimension 6 Data Integrity per X.805 Clause 6.6: Data Integrity ensures the correctness or accuracy of data. The data is protected against unauthorized modification + deletion + creation + replication and provides an indication of these unauthorized activities. Data Integrity covers both data at rest and data in transit ensuring the data remains accurate + complete + and unaltered except by authorized parties using authorized means. (1) Integrity Categories: (a) Connection-Oriented Integrity - integrity verified per connection + sequence numbers prevent replay + reorder; (b) Connectionless Integrity - integrity per message + each independently verifiable; (c) Selective Field Integrity - per field rather than per message; (d) Recovery vs Detection-Only - some mechanisms detect + others can restore via redundancy. (2) Cryptographic Integrity Mechanisms: (a) Hash Functions (SHA-256 + SHA-384 + SHA-512 + SHA-3 family per FIPS 202 + BLAKE2/3 + MD5 + SHA-1 DEPRECATED for security but legacy uses persist); (b) Message Authentication Codes (HMAC + KMAC + AES-CMAC + GMAC + Poly1305); (c) Authenticated Encryption with Associated Data (AEAD) - AES-GCM + AES-CCM + ChaCha20-Poly1305 (combined confidentiality + integrity); (d) Digital Signatures (RSA-PSS + ECDSA + EdDSA + ML-DSA + SLH-DSA + Falcon); (e) Merkle Trees - hash trees for efficient verification of large data + Bitcoin Block Header + Ethereum State + Certificate Transparency CT logs + Git commit chains; (f) Hash chains + Blockchain DLT immutable; (g) Erasure Coding + Reed-Solomon for integrity + availability; (h) Replication + Distributed Consensus (Paxos + Raft + PBFT). (3) Integrity at File System + Storage Level: (a) Filesystem Integrity (Btrfs checksumming + ZFS data scrubbing + ReFS); (b) RAID + erasure-coded storage; (c) WORM Write-Once-Read-Many storage; (d) Object Storage with Object Lock + S3 Object Lock + Azure Immutable Blob; (e) Backup integrity (immutable backups + ransomware-resistant + air-gapped); (f) HSM + TPM Trusted Platform Module attestation; (g) Secure Boot + Measured Boot. (4) File Integrity Monitoring (FIM): (a) FIM Tools (Tripwire + AIDE + Samhain + OSSEC + Wazuh + Auditd + Windows FCIV + Microsoft Defender + Falco for containers); (b) baseline hashing + change detection + alerting; (c) PCI DSS Req 11.5 FIM required; (d) HIPAA Security Rule Audit; (e) SOX IT controls; (f) NIST SP 800-53 SI-7 Software Firmware and Information Integrity. (5) Integrity in Communications: (a) TLS 1.3 record integrity via AEAD; (b) IPSec AH/ESP integrity; (c) DKIM email integrity; (d) DNSSEC DNS record signing; (e) SBOM Software Bill of Materials integrity for supply chain (SPDX + CycloneDX); (f) Code Signing + Authenticode + jarsigner + macOS notarisation. (6) Integrity per X.805 Layers: (a) Infrastructure - firmware + boot integrity + Secure Boot + Measured Boot + Remote Attestation; (b) Services - service-layer message integrity + AAA accounting record integrity + CDR integrity; (c) Applications - application data integrity + database constraints + API contract integrity. (7) Integrity per X.805 Planes: (a) Management - config integrity + signed configuration + change audit; (b) Control - signalling integrity + signed routing updates (BGPSEC + DNSSEC) + signed Diameter; (c) End-User - user data integrity + transaction integrity + e-banking transaction signing. (8) Threats Mitigated per X.805 Table 1: (a) Corruption (Y) - direct mitigation; (b) Removal (Y) - via redundancy + replication. (9) Modern Evolution: (a) Supply Chain Integrity - SLSA Supply-chain Levels for Software Artifacts + in-toto + Sigstore + Cosign + SLSA Provenance + SBOM (NIST EO 14028); (b) Container Image signing (Notary v2 + Cosign + Sigstore); (c) Code Signing for ML Models (Hugging Face Safetensors + Model cards); (d) Blockchain Integrity (Bitcoin + Ethereum + Hyperledger Fabric); (e) Distributed Ledger for audit trails; (f) Continuous Integrity Monitoring (CIM); (g) Post-Quantum Hash + Signature Migration. (10) Standards: (a) ISO/IEC 27001 A.12.2 + A.13.2.1 / A.5.34 A.8.13 A.8.7 (2022); (b) ISO/IEC 27040 Storage Security; (c) ITU-T X.815 Integrity Framework; (d) NIST SP 800-53 SI family + SI-7 SFI Integrity + SI-15 Tamper Resistance; (e) NIST SP 800-160 Vol 1 Trustworthy Secure Systems; (f) NIST SP 800-161 Supply Chain Risk Management; (g) FIPS 140-3 Cryptographic Module Validation; (h) FIPS 202 SHA-3; (i) PCI DSS Req 11.5; (j) HIPAA Security Rule. Coordinates with X.805 Layer 1/2/3 + Plane 1/2/3 + Threats Corruption/Removal + Security Dimension 1 Access Control + Security Dimension 3 Non-Repudiation + ITU-T X.815 Integrity Framework + ISO/IEC 27001 + 27040 + NIST SP 800-53 SI + 800-160 + 800-161 SCRM + FIPS 140-3 + 202 + IETF TLS 1.3 + IPSec + DNSSEC + DKIM + SLSA + in-toto + Sigstore + SBOM + Secure Boot + TPM. ITU-T X.805 Security Dimension 6 Data Integrity applies.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.