id: "SC-34" title: "Non-modifiable Executable Programs" family: "SC" family_name: "System and Communications Protection" sort_id: "sc-34" priority: "P1" implementation_level: "system" enhancements: - sc-34.1 - sc-34.2 - sc-34.3
Statement
For {{ insert: param, sc-34_odp.01 }} , load and execute:
The operating environment from hardware-enforced, read-only media; and
The following applications from hardware-enforced, read-only media: {{ insert: param, sc-34_odp.02 }}.
Guidance
The operating environment for a system contains the code that hosts applications, including operating systems, executives, or virtual machine monitors (i.e., hypervisors). It can also include certain applications that run directly on hardware platforms. Hardware-enforced, read-only media include Compact Disc-Recordable (CD-R) and Digital Versatile Disc-Recordable (DVD-R) disk drives as well as one-time, programmable, read-only memory. The use of non-modifiable storage ensures the integrity of software from the point of creation of the read-only image. The use of reprogrammable, read-only memory can be accepted as read-only media provided that integrity can be adequately protected from the point of initial writing to the insertion of the memory into the system, and there are reliable hardware protections against reprogramming the memory while installed in organizational systems.
Assessment Objective: the operating environment for {{ insert: param, sc-34_odp.01 }} is loaded and executed from hardware-enforced, read-only media;
Assessment Objective: {{ insert: param, sc-34_odp.02 }} for {{ insert: param, sc-34_odp.01 }} are loaded and executed from hardware-enforced, read-only media.
System and communications protection policy
procedures addressing non-modifiable executable programs
system design documentation
system configuration settings and associated documentation
system architecture
list of operating system components to be loaded from hardware-enforced, read-only media
list of applications to be loaded from hardware-enforced, read-only media
media used to load and execute the system operating environment
media used to load and execute system applications
system audit records
system security plan
other relevant documents or records
System/network administrators
organizational personnel with information security responsibilities
system developer
organizational personnel installing, configuring, and/or maintaining the system
system developers/integrators
Mechanisms supporting and/or implementing, loading, and executing the operating environment from hardware-enforced, read-only media
mechanisms supporting and/or implementing, loading, and executing applications from hardware-enforced, read-only media