Tamper Resistance and Detection
Tamper resistance and detection refers to physical and design measures that make it harder for someone to interfere with a device or system component, and to methods that reveal when such interference has occurred. Tamper resistance focuses on preventing or slowing unauthorized physical access, while tamper detection focuses on identifying that tampering was attempted or succeeded. These protections are generally used to safeguard systems and components as they move through the supply chain and while they are in operation.
In the context of NIST SP 800-53 Rev. 5 control SR-9, tamper resistance and detection are complementary safeguards intended to protect systems and system components during distribution and while in use, typically combined with strong identification to counter supply chain threats. Tamper resistance generally involves design and packaging measures that restrict or impede physical access to a device or component, such as hardened enclosures, locks, or chip-level access restrictions, making tampering more difficult and time-consuming. Tamper detection generally provides the capability to recognize that an attempt to access, open, or alter a component has occurred, for example when a chassis is opened, so that a response can be triggered. This entry addresses the general concept as reflected in the cited control and supporting technical literature; it does not cover specific implementation techniques, applicable baselines, agency tailoring, or contractual requirements, which the reader should verify against the current authoritative text of NIST SP 800-53 and any governing agency guidance.
Why it matters
Supply chain threats are among the most difficult to counter because a component can be interfered with long before it reaches the system where it is deployed, and because such interference may be invisible to operators unless the component is designed to reveal it. Tamper resistance and detection address both sides of this problem: resistance makes unauthorized physical access harder and more time-consuming, while detection provides a means to recognize that access, opening, or alteration has occurred. As reflected in NIST SP 800-53 Rev. 5 control SR-9, these safeguards are generally most effective when combined with strong identification, so that organizations can protect systems and components both during distribution and while in operation.
For defense and public sector organizations, the significance lies in the gap between compliance and assurance. A component may be procured through approved channels yet still be subject to tampering in transit or during storage, and without resistance or detection measures there may be no way to know. Tamper detection, for example, the ability to recognize when a chassis has been opened, allows an organization to trigger a response rather than continue to trust a component whose integrity may have been compromised.
Readers should treat this entry as a description of the general concept as reflected in the cited control and supporting technical literature. It does not establish which baselines apply, how a given agency may tailor the control, or what specific implementation techniques or contractual terms are required. Those specifics must be verified against the current authoritative text of NIST SP 800-53 and any governing agency guidance.
Who it's relevant to
Inside Tamper Resistance and Detection
Common questions
Answers to the questions practitioners most commonly ask about Tamper Resistance and Detection.