Signed Components

LOW MODERATE HIGH
0 Overlays 4 Related Controls
Graph
Export ▾

Requirements NIST SOURCE

Prevent the installation of [organization-defined software and firmware components] without verification that the component has been digitally signed using a certificate that is recognized and approved by the organization.

Discussion (NIST Supplemental Guidance)

Software and firmware components prevented from installation unless signed with recognized and approved certificates include software and firmware version updates, patches, service packs, device drivers, and basic input/output system updates. Organizations can identify applicable software and firmware components by type, by specific items, or a combination of both. Digital signatures and organizational verification of such signatures is a method of code authentication.

Implementation Guidance

Engineering Interpretation

Original engineering commentary written for this explorer — not NIST source text and not authoritative guidance.

No engineering interpretation has been authored for CM-14 yet. This section is architected to receive it — see the Requirements and Assessment sections above for the authoritative NIST source content in the meantime.

Assessment

NIST SP 800-53A REV 5.2.0

Assessment Objectives

  1. software components requiring verification of a digitally signed certificate before installation are defined;
  2. firmware components requiring verification of a digitally signed certificate before installation are defined;
  3. the installation of <CM-14_ODP[01] software components> is prevented unless it is verified that the software has been digitally signed using a certificate recognized and approved by the organization;
  4. the installation of <CM-14_ODP[02] firmware components> is prevented unless it is verified that the firmware has been digitally signed using a certificate recognized and approved by the organization.

Examine

[SELECT FROM: Configuration management policy; procedures addressing digitally signed certificates for software and firmware components; configuration management plan; system security plan; system design documentation; change control records; system component inventory; system security plan; other relevant documents or records].

Interview

[SELECT FROM: Organizational personnel with responsibilities for verifying digitally signed certificates for software and firmware component installation; organizational personnel with information security responsibilities; system/network administrators; system developers].

Test

[SELECT FROM: Organizational processes governing information location; mechanisms enforcing policies and methods for governing information location; automated tools supporting or implementing digitally signatures for software and firmware components; automated tools supporting or implementing verification of digital signatures for software and firmware component installation].

STIGs & CCIs

No STIG checks or CCI mappings are currently loaded for CM-14. This section is architected to display, per product: STIG ID, Finding ID, Severity, Title, Description, Check, Fix, CCI, and NIST control mapping — but nothing is populated here until a real DISA STIG/CCI dataset is ingested.

Learn more about STIG/CCI integration →

Evidence

Potential Evidence — Derived

Categorized from the SP 800-53A "Examine"/"Test" artifact list above by keyword — not an authoritative NIST evidence list.

Policy

  • system security plan

Configuration

  • Configuration management policy
  • configuration management plan
  • system design documentation
  • system component inventory

Testing

  • Organizational processes governing information location
  • mechanisms enforcing policies and methods for governing information location
  • automated tools supporting or implementing digitally signatures for software and firmware components
  • automated tools supporting or implementing verification of digital signatures for software and firmware component installation

Other Records

  • procedures addressing digitally signed certificates for software and firmware components
  • change control records
  • other relevant documents or records