CM 14 SIGNED COMPONENTS - NIST-SP-800-53-R5/NIST-SP-800-53-R5.github.io GitHub Wiki

CM-14 SIGNED COMPONENTS

Control: Prevent the installation of [ Assignment: organization-defined software and firmware components ] without verification that the component has been digitally signed using a certificate that is recognized and approved by the organization.

Discussion: Software and firmware components prevented from installation unless signed with recognized and approved certificates include software and firmware version updates, patches, service packs, device drivers, and basic input/output system updates. Organizations can identify applicable software and firmware components by type, by specific items, or a combination of both. Digital signatures and organizational verification of such signatures is a method of code authentication.

Related Controls: CM-7, SC-12, SC-13, SI-7.

References: [IR 8062].

⚠️ **GitHub.com Fallback** ⚠️