id: "SC-34" title: "Non-modifiable Executable Programs" family: "SC" family_name: "System and Communications Protection" sort_id: "sc-34" priority: "P1" implementation_level: "system" enhancements: - sc-34.1 - sc-34.2 - sc-34.3


Statement

For {{ insert: param, sc-34_odp.01 }} , load and execute:

The operating environment from hardware-enforced, read-only media; and

The following applications from hardware-enforced, read-only media: {{ insert: param, sc-34_odp.02 }}.

Guidance

The operating environment for a system contains the code that hosts applications, including operating systems, executives, or virtual machine monitors (i.e., hypervisors). It can also include certain applications that run directly on hardware platforms. Hardware-enforced, read-only media include Compact Disc-Recordable (CD-R) and Digital Versatile Disc-Recordable (DVD-R) disk drives as well as one-time, programmable, read-only memory. The use of non-modifiable storage ensures the integrity of software from the point of creation of the read-only image. The use of reprogrammable, read-only memory can be accepted as read-only media provided that integrity can be adequately protected from the point of initial writing to the insertion of the memory into the system, and there are reliable hardware protections against reprogramming the memory while installed in organizational systems.

Assessment Objective: the operating environment for {{ insert: param, sc-34_odp.01 }} is loaded and executed from hardware-enforced, read-only media;

Assessment Objective: {{ insert: param, sc-34_odp.02 }} for {{ insert: param, sc-34_odp.01 }} are loaded and executed from hardware-enforced, read-only media.

System and communications protection policy

procedures addressing non-modifiable executable programs

system design documentation

system configuration settings and associated documentation

system architecture

list of operating system components to be loaded from hardware-enforced, read-only media

list of applications to be loaded from hardware-enforced, read-only media

media used to load and execute the system operating environment

media used to load and execute system applications

system audit records

system security plan

other relevant documents or records

System/network administrators

organizational personnel with information security responsibilities

system developer

organizational personnel installing, configuring, and/or maintaining the system

system developers/integrators

Mechanisms supporting and/or implementing, loading, and executing the operating environment from hardware-enforced, read-only media

mechanisms supporting and/or implementing, loading, and executing applications from hardware-enforced, read-only media