id: "SA-10(01)" title: "Software and Firmware Integrity Verification" family: "SA" family_name: "System and Services Acquisition" sort_id: "sa-10.01" priority: "P1" implementation_level: "organization" parent: "SA-10" enhancement: True


Statement

Require the developer of the system, system component, or system service to enable integrity verification of software and firmware components.

Guidance

Software and firmware integrity verification allows organizations to detect unauthorized changes to software and firmware components using developer-provided tools, techniques, and mechanisms. The integrity checking mechanisms can also address counterfeiting of software and firmware components. Organizations verify the integrity of software and firmware components, for example, through secure one-way hashes provided by developers. Delivered software and firmware components also include any updates to such components.

Assessment Objective

the developer of the system, system component, or system service is required to enable integrity verification of software and firmware components.

System and services acquisition policy

procedures addressing system developer configuration management

solicitation documentation

acquisition documentation

service level agreements

acquisition contracts for the system, system component, or system service

system developer configuration management plan

software and firmware integrity verification records

system change authorization records

change control records

configuration management records

system security plan

supply chain risk management plan

other relevant documents or records

Organizational personnel with system and service acquisition responsibilities

organizational personnel with information security responsibilities

organizational personnel with configuration management responsibilities

system developers

organizational personnel with supply chain risk management responsibilities

Organizational processes for monitoring developer configuration management

mechanisms supporting and/or implementing the monitoring of developer configuration management