SC-34(3): Hardware-Based Protection

Threats Addressed:


(Not part of any baseline)

Control is withdrawn in the next version of this control set and incorporated into: SC-51: Hardware-based Protection.

Control Statement

The organization:

  1. Employs hardware-based, write-protect for [Assignment: organization-defined information system firmware components]; and
  2. Implements specific procedures for [Assignment: organization-defined authorized individuals] to manually disable hardware write-protect for firmware modifications and re-enable the write-protect prior to returning to operational mode.