Non-modifiable Executable Programs

LOW MODERATE HIGH
2 Enhancements 0 Overlays 3 Related Controls
Graph
Export ▾

Requirements NIST SOURCE

For [system components] , load and execute:

Discussion (NIST Supplemental Guidance)

The operating environment for a system contains the code that hosts applications, including operating systems, executives, or virtual machine monitors (i.e., hypervisors). It can also include certain applications that run directly on hardware platforms. Hardware-enforced, read-only media include Compact Disc-Recordable (CD-R) and Digital Versatile Disc-Recordable (DVD-R) disk drives as well as one-time, programmable, read-only memory. The use of non-modifiable storage ensures the integrity of software from the point of creation of the read-only image. The use of reprogrammable, read-only memory can be accepted as read-only media provided that integrity can be adequately protected from the point of initial writing to the insertion of the memory into the system, and there are reliable hardware protections against reprogramming the memory while installed in organizational systems.

Enhancements NIST SOURCE

SC-34(1) No Writable Storage LOW MODERATE HIGH

Employ [system components] with no writeable storage that is persistent across component restart or power on/off.

Discussion

Disallowing writeable storage eliminates the possibility of malicious code insertion via persistent, writeable storage within the designated system components. The restriction applies to fixed and removable storage, with the latter being addressed either directly or as specific restrictions imposed through access controls for mobile devices.

Open full page for SC-34(1) →
SC-34(2) Integrity Protection on Read-only Media LOW MODERATE HIGH

Protect the integrity of information prior to storage on read-only media and control the media after such information has been recorded onto the media.

Discussion

Controls prevent the substitution of media into systems or the reprogramming of programmable read-only media prior to installation into the systems. Integrity protection controls include a combination of prevention, detection, and response.

Open full page for SC-34(2) →
SC-34(3) Hardware-based Protection WITHDRAWN

Withdrawn from the catalog.

Implementation Guidance

Engineering Interpretation

Original engineering commentary written for this explorer — not NIST source text and not authoritative guidance.

No engineering interpretation has been authored for SC-34 yet. This section is architected to receive it — see the Requirements and Assessment sections above for the authoritative NIST source content in the meantime.

Assessment

NIST SP 800-53A REV 5.2.0

Assessment Objectives

  1. system components for which the operating environment and applications are to be loaded and executed from hardware-enforced, read-only media are defined;
  2. applications to be loaded and executed from hardware-enforced, read-only media are defined;
  3. the operating environment for <SC-34_ODP[01] system components> is loaded and executed from hardware-enforced, read-only media;
  4. <SC-34_ODP[02] applications> for <SC-34_ODP[01] system components> are loaded and executed from hardware-enforced, read-only media.

Examine

[SELECT FROM: System and communications protection policy; procedures addressing non-modifiable executable programs; system design documentation; system configuration settings and associated documentation; system architecture; list of operating system components to be loaded from hardware-enforced, read-only media; list of applications to be loaded from hardware-enforced, read-only media; media used to load and execute the system operating environment; media used to load and execute system applications; system audit records; system security plan; other relevant documents or records].

Interview

[SELECT FROM: System/network administrators; organizational personnel with information security responsibilities; system developer; organizational personnel installing, configuring, and/or maintaining the system; system developers/integrators].

Test

[SELECT FROM: Mechanisms supporting and/or implementing, loading, and executing the operating environment from hardware-enforced, read-only media; mechanisms supporting and/or implementing, loading, and executing applications from hardware-enforced, read-only media].

STIGs & CCIs

No STIG checks or CCI mappings are currently loaded for SC-34. This section is architected to display, per product: STIG ID, Finding ID, Severity, Title, Description, Check, Fix, CCI, and NIST control mapping — but nothing is populated here until a real DISA STIG/CCI dataset is ingested.

Learn more about STIG/CCI integration →

Evidence

Potential Evidence — Derived

Categorized from the SP 800-53A "Examine"/"Test" artifact list above by keyword — not an authoritative NIST evidence list.

Policy

  • System and communications protection policy
  • system security plan

Configuration

  • system design documentation
  • system configuration settings and associated documentation
  • system architecture

Testing

  • Mechanisms supporting and/or implementing, loading, and executing the operating environment from hardware-enforced, read-only media
  • mechanisms supporting and/or implementing, loading, and executing applications from hardware-enforced, read-only media

Other Records

  • procedures addressing non-modifiable executable programs
  • list of operating system components to be loaded from hardware-enforced, read-only media
  • list of applications to be loaded from hardware-enforced, read-only media
  • media used to load and execute the system operating environment
  • media used to load and execute system applications
  • system audit records
  • other relevant documents or records