PR.PS-05.254

Does your organization have a process to verify the authenticity and integrity of software before installation?

Explanation

Software integrity verification is the subject, specifically whether you confirm that software comes from a legitimate source and has not been tampered with before it is installed. This includes checking digital signatures, verifying checksums, downloading from official repositories or vendor websites, and confirming software hasn't been modified in transit.

Evidence could include a documented software verification procedure, screenshots of checksum verification processes, logs showing signature verification, or a software installation policy that mandates source and integrity verification steps.

Implementation Example

Verify the source of new software and the software's integrity before installing it

ID: PR.PS-05.254

Context

Function
PR: PROTECT
Category
PR.PS: Platform Security
Sub-Category
Installation and execution of unauthorized software are prevented

Related questions