id: "SI-07(10)" title: "Protection of Boot Firmware" family: "SI" family_name: "System and Information Integrity" sort_id: "si-07.10" priority: "P1" implementation_level: "system" parent: "SI-07" enhancement: True


Statement

Implement the following mechanisms to protect the integrity of boot firmware in {{ insert: param, si-07.10_odp.02 }}: {{ insert: param, si-07.10_odp.01 }}.

Guidance

Unauthorized modifications to boot firmware may indicate a sophisticated, targeted attack. These types of targeted attacks can result in a permanent denial of service or a persistent malicious code presence. These situations can occur if the firmware is corrupted or if the malicious code is embedded within the firmware. System components can protect the integrity of boot firmware in organizational systems by verifying the integrity and authenticity of all updates to the firmware prior to applying changes to the system component and preventing unauthorized processes from modifying the boot firmware.

Assessment Objective

{{ insert: param, si-07.10_odp.01 }} are implemented to protect the integrity of boot firmware in {{ insert: param, si-07.10_odp.02 }}.

System and information integrity policy

system and information integrity procedures

procedures addressing software, firmware, and information integrity

system design documentation

system configuration settings and associated documentation

integrity verification tools and associated documentation

records of integrity verification scans

system audit records

system security plan

other relevant documents or records

Organizational personnel responsible for software, firmware, and/or information integrity

organizational personnel with information security responsibilities

system/network administrators

system developer

Software, firmware, and information integrity verification tools

mechanisms supporting and/or implementing protection of the integrity of boot firmware

safeguards implementing protection of the integrity of boot firmware