CHG-04.2 ยท Signed Components

Control Description

Mechanisms exist to prevent the installation of software and firmware components without verification that the component has been digitally signed using an organization-approved certificate authority.

Control Question
Assessment question for control validation

Does the organization prevent the installation of software and firmware components without verification that the component has been digitally signed using an organization-approved certificate authority?

Control Weighting
3
Validation Cadence
Annual
NIST CSF Function
Protect
Supply Chain Risk Management (SCRM) Tiers
Applicable SCRM tier levels for this control
Tier 3 - Tactical