Non-modifiable Executable Programs
LOW MODERATE HIGHRequirements NIST SOURCE
For [system components] , load and execute:
Requirement Context
This element is part of SC-34 — Non-modifiable Executable Programs. See the Assessment section below for the related SP 800-53A examine/interview/test procedures. No engineering interpretation has been authored for this control yet.
Requirement Context
This element is part of SC-34 — Non-modifiable Executable Programs. See the Assessment section below for the related SP 800-53A examine/interview/test procedures. No engineering interpretation has been authored for this control yet.
Discussion (NIST Supplemental Guidance)
The operating environment for a system contains the code that hosts applications, including operating systems, executives, or virtual machine monitors (i.e., hypervisors). It can also include certain applications that run directly on hardware platforms. Hardware-enforced, read-only media include Compact Disc-Recordable (CD-R) and Digital Versatile Disc-Recordable (DVD-R) disk drives as well as one-time, programmable, read-only memory. The use of non-modifiable storage ensures the integrity of software from the point of creation of the read-only image. The use of reprogrammable, read-only memory can be accepted as read-only media provided that integrity can be adequately protected from the point of initial writing to the insertion of the memory into the system, and there are reliable hardware protections against reprogramming the memory while installed in organizational systems.
Enhancements NIST SOURCE
SC-34(1) No Writable Storage LOW MODERATE HIGH
Employ [system components] with no writeable storage that is persistent across component restart or power on/off.
Discussion
Disallowing writeable storage eliminates the possibility of malicious code insertion via persistent, writeable storage within the designated system components. The restriction applies to fixed and removable storage, with the latter being addressed either directly or as specific restrictions imposed through access controls for mobile devices.
SC-34(2) Integrity Protection on Read-only Media LOW MODERATE HIGH
Protect the integrity of information prior to storage on read-only media and control the media after such information has been recorded onto the media.
Discussion
Controls prevent the substitution of media into systems or the reprogramming of programmable read-only media prior to installation into the systems. Integrity protection controls include a combination of prevention, detection, and response.
SC-34(3) Hardware-based Protection WITHDRAWN
Withdrawn from the catalog.
Implementation Guidance
Original engineering commentary written for this explorer — not NIST source text and not authoritative guidance.
No engineering interpretation has been authored for SC-34 yet. This section is architected to receive it — see the Requirements and Assessment sections above for the authoritative NIST source content in the meantime.
Assessment
Assessment Objectives
- system components for which the operating environment and applications are to be loaded and executed from hardware-enforced, read-only media are defined;
- applications to be loaded and executed from hardware-enforced, read-only media are defined;
- the operating environment for <SC-34_ODP[01] system components> is loaded and executed from hardware-enforced, read-only media;
- <SC-34_ODP[02] applications> for <SC-34_ODP[01] system components> are loaded and executed from hardware-enforced, read-only media.
Examine
[SELECT FROM: System and communications protection policy; procedures addressing non-modifiable executable programs; system design documentation; system configuration settings and associated documentation; system architecture; list of operating system components to be loaded from hardware-enforced, read-only media; list of applications to be loaded from hardware-enforced, read-only media; media used to load and execute the system operating environment; media used to load and execute system applications; system audit records; system security plan; other relevant documents or records].
Interview
[SELECT FROM: System/network administrators; organizational personnel with information security responsibilities; system developer; organizational personnel installing, configuring, and/or maintaining the system; system developers/integrators].
Test
[SELECT FROM: Mechanisms supporting and/or implementing, loading, and executing the operating environment from hardware-enforced, read-only media; mechanisms supporting and/or implementing, loading, and executing applications from hardware-enforced, read-only media].
STIGs & CCIs
No STIG checks or CCI mappings are currently loaded for SC-34. This section is architected to display, per product: STIG ID, Finding ID, Severity, Title, Description, Check, Fix, CCI, and NIST control mapping — but nothing is populated here until a real DISA STIG/CCI dataset is ingested.
Learn more about STIG/CCI integration →Evidence
Categorized from the SP 800-53A "Examine"/"Test" artifact list above by keyword — not an authoritative NIST evidence list.
Policy
- System and communications protection policy
- system security plan
Configuration
- system design documentation
- system configuration settings and associated documentation
- system architecture
Testing
- Mechanisms supporting and/or implementing, loading, and executing the operating environment from hardware-enforced, read-only media
- mechanisms supporting and/or implementing, loading, and executing applications from hardware-enforced, read-only media
Other Records
- procedures addressing non-modifiable executable programs
- list of operating system components to be loaded from hardware-enforced, read-only media
- list of applications to be loaded from hardware-enforced, read-only media
- media used to load and execute the system operating environment
- media used to load and execute system applications
- system audit records
- other relevant documents or records