Mechanisms exist to ensure software and/or firmware patches are: (1) Obtained from trusted sources; and (2) Checked for integrity.
Does the organization ensure software and/or firmware patches are: (1) Obtained from trusted sources; and (2) Checked for integrity?