Skip to content

CM-14: Signed Components

An OSCAL Control

Statement

    • Prevent the installation of without verification that the component has been digitally signed using a certificate that is recognized and approved by the organization.

      • Guidance:

        If digital signatures/certificates are unavailable, alternative cryptographic integrity checks (hashes, self-signed certs, etc.) can be utilized.