# Embed reliability, authenticity, integrity, usability, and disposition in electronic records systems

> Use 36 CFR 1236.10 - Controls for electronic information systems to review this narrow operational decision without extending the source beyond its stated scope.

- Canonical URL: https://update.dsesecurity.com/updates/embed-reliability-authenticity-integrity-usability-and-disposition-in-electronic-records-systems/
- Publisher: Detection Systems & Engineering (DSE Security)
- Author: DSE Security Editorial Team
- Published: 2026-08-27T12:11:28+00:00
- Modified: 2026-08-27T13:07:00+00:00
- Last reviewed by DSE: 2026-08-26
- Resource type: Explainer
- DSE priority: Advisory
- Topics: Business Continuity, Cybersecurity
- Reading time: 3 minutes

## What you need to know

Use 36 CFR 1236.10 - Controls for electronic information systems to review this narrow operational decision without extending the source beyond its stated scope.

## Potentially affected

Teams, systems, services, or facilities within the stated scope of 36 CFR 1236.10 - Controls for electronic information systems

## DSE recommendation

Compare the observed state with the cited official source, document applicability and exceptions, and test any approved change with rollback safeguards.

## Article

Frame this document as a source-led configuration and assurance check: Embed reliability, authenticity, integrity, usability, and disposition in electronic records systems. Only the official source and traced locations below supply facts. Confirm applicability before acting.

## Source fact:

The official [36 CFR 1236.10 – Controls for electronic information systems](https://www.ecfr.gov/current/title-36/section-1236.10) from National Archives and Records Administration via eCFR supports the following bounded statements:

- Under 36 CFR 1236, agencies must establish integrity controls, such as audit trails, so records in electronic information systems remain complete and unaltered. The research record locates this support at 36 CFR 1236.10(c), read with the unnumbered introductory paragraph of 36 CFR 1236.10 (eCFR anchor p-1236.10(c)).

- Under 36 CFR 1236, agencies must use structure controls that preserve records’ physical and logical formats and the relationships among their data elements. The research record locates this support at 36 CFR 1236.10(g), read with the unnumbered introductory paragraph of 36 CFR 1236.10 (eCFR anchor p-1236.10(g)).

Do not import neighboring assumptions into the source record. The supported task is a scoped comparison involving essential functions, upstream providers, recovery sequences, alternate work paths, and tested recovery objectives and the conditions the source actually describes.

## What the source does not establish

Federal agency records-management regulation; system scope, record status, schedules, metadata, security, privacy, migrations, and NARA guidance require records-professional review. It does not establish a deployment’s current state, authorize a production change, prove compliance, or show that identity, DNS, communications, facilities, suppliers, and the people authorized to invoke recovery are healthy. Documented options are review inputs, not universal mandates.

## Applicability questions

- For source statement 1 at 36 CFR 1236.10(c), read with the unnumbered introductory paragraph of 36 CFR 1236.10 (eCFR anchor p-1236.10(c)), which observable configuration, record, or test can confirm applicability here?

- For source statement 2 at 36 CFR 1236.10(g), read with the unnumbered introductory paragraph of 36 CFR 1236.10 (eCFR anchor p-1236.10(g)), which observable configuration, record, or test can confirm applicability here?

- Which owner can attest to the recorded state of essential functions, upstream providers, recovery sequences, alternate work paths, and tested recovery objectives, including exceptions?

- What baseline for identity, DNS, communications, facilities, suppliers, and the people authorized to invoke recovery must accompany the source-specific observation?

- Which success, stop, and escalation criteria are written before testing begins?

## DSE recommendation:

DSE recommends using the cited source as the evidence anchor for this decision. Use a two-person review for the source interpretation and the resulting operational decision. Record the source location, examined part of essential functions, upstream providers, recovery sequences, alternate work paths, and tested recovery objectives, observed and expected states, owner, and reason for deviation.

Translate the conclusion into change control only after documenting dependencies, impact, test method, expected signals, failure signals, and restoration steps. Include identity, DNS, communications, facilities, suppliers, and the people authorized to invoke recovery, while excluding secrets and sensitive personal or topology data from ordinary tickets.

## Verification and evidence

Keep the source locations 36 CFR 1236.10(c), read with the unnumbered introductory paragraph of 36 CFR 1236.10 (eCFR anchor p-1236.10(c)); 36 CFR 1236.10(g), read with the unnumbered introductory paragraph of 36 CFR 1236.10 (eCFR anchor p-1236.10(g)) adjacent to the sanitized artifacts used for comparison. Prefer business-impact records, dependency maps, exercise results, recovery timings, and open corrective actions, with enough identity and timing data for an independent recheck.

Record the decision even when no change is made, including uncertainty and the next trigger. Use safe testing conditions for disruptive work, preserve rollback proof, and revisit the conclusion after relevant platform, dependency, vendor, or ownership changes.

## Official references

- [36 CFR 1236.10 – Controls for electronic information systems](https://www.ecfr.gov/current/title-36/section-1236.10) — National Archives and Records Administration via eCFR

## Primary reference

- Name: 36 CFR 1236.10 - Controls for electronic information systems
- Authority: www.ecfr.gov
- URL: https://www.ecfr.gov/current/title-36/section-1236.10
- Source publication date: Not stated by the source

## Citation and use

Preferred citation: “Embed reliability, authenticity, integrity, usability, and disposition in electronic records systems,” DSE Security, https://update.dsesecurity.com/updates/embed-reliability-authenticity-integrity-usability-and-disposition-in-electronic-records-systems/
Publishing principles: https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/
Usage and citation policy: https://update.dsesecurity.com/usage/
Copyright © 2026 Detection Systems & Engineering. All rights reserved.
