id: "SA-10(01)" title: "Software and Firmware Integrity Verification" family: "SA" family_name: "System and Services Acquisition" sort_id: "sa-10.01" priority: "P1" implementation_level: "organization" parent: "SA-10" enhancement: True
Statement
Require the developer of the system, system component, or system service to enable integrity verification of software and firmware components.
Guidance
Software and firmware integrity verification allows organizations to detect unauthorized changes to software and firmware components using developer-provided tools, techniques, and mechanisms. The integrity checking mechanisms can also address counterfeiting of software and firmware components. Organizations verify the integrity of software and firmware components, for example, through secure one-way hashes provided by developers. Delivered software and firmware components also include any updates to such components.
Assessment Objective
the developer of the system, system component, or system service is required to enable integrity verification of software and firmware components.
System and services acquisition policy
procedures addressing system developer configuration management
solicitation documentation
acquisition documentation
service level agreements
acquisition contracts for the system, system component, or system service
system developer configuration management plan
software and firmware integrity verification records
system change authorization records
change control records
configuration management records
system security plan
supply chain risk management plan
other relevant documents or records
Organizational personnel with system and service acquisition responsibilities
organizational personnel with information security responsibilities
organizational personnel with configuration management responsibilities
system developers
organizational personnel with supply chain risk management responsibilities
Organizational processes for monitoring developer configuration management
mechanisms supporting and/or implementing the monitoring of developer configuration management