SI-7(15): Code Authentication
Control Family:
Parent Control:
CSF v1.1 References:
PF v1.0 References:
Threats Addressed:
Baselines:
- High
- OT High (SP 800-82r3)
Previous Version:
- NIST Special Publication 800-53 Revision 4:
- SI-7(15): Code Authentication
Control Statement
Implement cryptographic mechanisms to authenticate the following software or firmware components prior to installation: [Assignment: organization-defined software or firmware components].
Supplemental Guidance
Cryptographic authentication includes verifying that software or firmware components have been digitally signed using certificates recognized and approved by organizations. Code signing is an effective method to protect against malicious code. Organizations that employ cryptographic mechanisms also consider cryptographic key management solutions.
OT Discussion
Code authentication provides assurance that the software and firmware have not been tampered with. If automated mechanisms are not available, organizations could manually verify code authentication by using a combination of techniques, including verifying hashes, downloading from reputable sources, verifying version numbers with the vendor, or testing software and firmware in offline or test environments.