Skip to main content

πŸ’Ό CM-14 Signed Components (H)

  • Contextual name: πŸ’Ό CM-14 Signed Components (H)
  • ID: /frameworks/fedramp-high-security-controls/cm/14
  • Located in: πŸ’Ό Configuration Management

Description​

Prevent the installation of [Assignment: organization-defined software and firmware components] without verification that the component has been digitally signed using a certificate that is recognized and approved by the organization. CM-14 Additional FedRAMP Requirements and Guidance: Guidance: If digital signatures/certificates are unavailable, alternative cryptographic integrity checks (hashes, self-signed certs, etc.) can be utilized.

Similar​

  • Sections
    • /frameworks/nist-sp-800-53-r5/cm/14
  • Internal
    • ID: dec-c-e425bf35

Similar Sections (Take Policies From)​

SectionSub SectionsInternal RulesPoliciesFlags
πŸ’Ό NIST SP 800-53 Revision 5 β†’ πŸ’Ό CM-14 Signed Components

Sub Sections​

SectionSub SectionsInternal RulesPoliciesFlags