800-53|CM-5(3)

Title

SIGNED COMPONENTS

Description

The information system prevents the installation of [Assignment: organization-defined software and firmware components] without verification that the component has been digitally signed using a certificate that is recognized and approved by the organization.

Supplemental

Software and firmware components prevented from installation unless signed with recognized and approved certificates include, for example, software and firmware version updates, patches, service packs, device drivers, and basic input output system (BIOS) updates. Organizations can identify applicable software and firmware components by type, by specific items, or a combination of both. Digital signatures and organizational verification of such signatures, is a method of code authentication.

Reference Item Details

Related: CM-7,SC-13,SI-7

Category: CONFIGURATION MANAGEMENT

Parent Title: ACCESS RESTRICTIONS FOR CHANGE

Family: CONFIGURATION MANAGEMENT

Baseline Impact: HIGH

Audit Items

View all Reference Audit Items

NamePluginAudit Name
1.2 AZLX-23-000110UnixCIS Amazon Linux 2023 STIG v1.0.0 CAT II
1.2.1.2 Ensure gpgcheck is configuredUnixCIS Oracle Linux 8 v4.0.0 L1 Server
1.2.1.2 Ensure gpgcheck is configuredUnixCIS AlmaLinux OS 8 v4.0.0 L1 Server
1.2.1.2 Ensure gpgcheck is configuredUnixCIS Oracle Linux 10 v1.0.0 L1 Workstation
1.2.1.2 Ensure gpgcheck is configuredUnixCIS Red Hat Enterprise Linux 10 v1.0.1 L1 Server
1.2.1.2 Ensure gpgcheck is configuredUnixCIS AlmaLinux OS 10 v1.0.0 L1 Server
1.2.1.2 Ensure gpgcheck is configuredUnixCIS Oracle Linux 8 v4.0.0 L1 Workstation
1.2.1.2 Ensure gpgcheck is configuredUnixCIS AlmaLinux OS 10 v1.0.0 L1 Workstation
1.2.1.2 Ensure gpgcheck is configuredUnixCIS Rocky Linux 8 v3.0.0 L1 Server
1.2.1.2 Ensure gpgcheck is configuredUnixCIS Rocky Linux 8 v3.0.0 L1 Workstation
1.2.1.2 Ensure gpgcheck is configuredUnixCIS Red Hat Enterprise Linux 8 v4.0.0 L1 Server
1.2.1.2 Ensure gpgcheck is configuredUnixCIS Red Hat Enterprise Linux 8 v4.0.0 L1 Workstation
1.2.1.2 Ensure gpgcheck is configuredUnixCIS AlmaLinux OS 8 v4.0.0 L1 Workstation
1.2.1.2 Ensure gpgcheck is configuredUnixCIS Red Hat Enterprise Linux 10 v1.0.1 L1 Workstation
1.2.1.2 Ensure gpgcheck is configuredUnixCIS Rocky Linux 10 v1.0.0 L1 Server
1.2.1.2 Ensure gpgcheck is configuredUnixCIS Rocky Linux 10 v1.0.0 L1 Workstation
1.2.1.2 Ensure gpgcheck is configuredUnixCIS Oracle Linux 10 v1.0.0 L1 Server
1.2.1.5 Ensure DNF is configured to perform a signature check on local packagesUnixCIS Red Hat Enterprise Linux 8 STIG v2.0.0 STIG
1.2.1.6 Ensure cryptographic verification of vendor software packagesUnixCIS Red Hat Enterprise Linux 8 STIG v2.0.0 STIG
1.2.3 Ensure gpgcheck is globally activatedUnixCIS Amazon Linux 2 STIG v2.0.1 STIG
1.2.3 Ensure gpgcheck is globally activatedUnixCIS Amazon Linux 2 STIG v2.0.1 L1 Server
1.2.3 Ensure gpgcheck is globally activated - CA that is recognized and approved by the organization.UnixCIS Red Hat Enterprise Linux 7 STIG v2.0.0 STIG
1.2.4 Ensure software packages have been digitally signed by a Certificate Authority (CA)UnixCIS Amazon Linux 2 STIG v2.0.1 STIG
1.2.6 Ensure software packages have been digitally signed by a Certificate Authority (CA) - CA that is recognized and approved by the organization.UnixCIS Red Hat Enterprise Linux 7 STIG v2.0.0 STIG
1.3 AZLX-23-000115UnixCIS Amazon Linux 2023 STIG v1.0.0 CAT I
1.3 OL08-00-010019UnixCIS Oracle Linux 8 STIG v1.0.0 CAT II
1.4 AZLX-23-000120UnixCIS Amazon Linux 2023 STIG v1.0.0 CAT I
1.5 AZLX-23-000125UnixCIS Amazon Linux 2023 STIG v1.0.0 CAT I
1.5.12 Ensure kernel image loading is disabledUnixCIS Red Hat Enterprise Linux 8 STIG v2.0.0 STIG
1.10 RHEL-10-001020UnixCIS Red Hat Enterprise Linux 10 STIG v1.0.0 CAT II
1.11 RHEL-10-001030UnixCIS Red Hat Enterprise Linux 10 STIG v1.0.0 CAT I
1.12 RHEL-10-001040UnixCIS Red Hat Enterprise Linux 10 STIG v1.0.0 CAT I
1.13 EX19-ED-000053WindowsCIS Microsoft Exchange 2019 Edge Server STIG v1.0.0 CAT II
1.13 RHEL-10-001050UnixCIS Red Hat Enterprise Linux 10 STIG v1.0.0 CAT I
1.20 EX19-MB-000061WindowsCIS Microsoft Exchange 2019 Mailbox Server STIG v1.0.0 CAT II
1.23 RHEL-09-213020UnixCIS Red Hat Enterprise Linux 9 STIG v1.0.0 CAT II
1.24 RHEL-10-200500UnixCIS Red Hat Enterprise Linux 10 STIG v1.0.0 CAT II
1.34 SOL-11.1-020020UnixCIS Solaris 11 X86 STIG v1.0.0 CAT II
1.34 SOL-11.1-020020UnixCIS Solaris 11 SPARC STIG v1.0.0 CAT II
1.43 RHEL-09-214010UnixCIS Red Hat Enterprise Linux 9 STIG v1.0.0 CAT II
1.44 RHEL-09-214015UnixCIS Red Hat Enterprise Linux 9 STIG v1.0.0 CAT I
1.45 RHEL-09-214020UnixCIS Red Hat Enterprise Linux 9 STIG v1.0.0 CAT I
1.46 PHTN-40-000130UnixCIS VMware vSphere 8.0 vCenter Appliance Photon OS 4.0 STIG v1.0.0 CAT I
1.46 RHEL-09-214025UnixCIS Red Hat Enterprise Linux 9 STIG v1.0.0 CAT I
1.49 RHEL-09-215010UnixCIS Red Hat Enterprise Linux 9 STIG v1.0.0 CAT II
1.52 UBTU-24-300001UnixCIS Ubuntu Linux 24.04 LTS STIG v1.0.0 CAT III
1.54 SLES-15-010430UnixCIS SUSE Linux Enterprise Server 15 STIG v1.0.0 CAT I
1.182 AZLX-23-002575UnixCIS Amazon Linux 2023 STIG v1.0.0 CAT II
1.327 OL09-00-002428UnixCIS Oracle Linux 9 STIG v1.0.0 CAT II
1.376 RHEL-10-701050UnixCIS Red Hat Enterprise Linux 10 STIG v1.0.0 CAT I