CCI-001749
The information system prevents the installation of organization-defined software components without verification the software component has been digitally signed using a certificate that is recognized and approved by the organization.
Docker Incs official GPG key must be added to the host using the users operating systems respective package repository management tooling.
1 rule found Severity: Low

The FortiGate device must only install patches or updates that are validated by the vendor via digital signature or hash.
1 rule found Severity: Medium

The DataPower Gateway must prevent the installation of patches, service packs, or application components without verification the software component has been digitally signed using a certificate that is recognized and approved by the organization.
1 rule found Severity: Medium

7 rules found Severity: Medium

7 rules found Severity: Medium

13 rules found Severity: Medium

8 rules found Severity: Medium

2 rules found Severity: Medium

1 rule found Severity: Medium

1 rule found Severity: Medium

Nutanix AOS must prevent the installation of patches, service packs, device drivers, or operating system components without verification they have been digitally signed using a certificate that is recognized and approved by the organization.
1 rule found Severity: Medium

The Tanium cryptographic signing capabilities must be enabled on the Tanium Clients, which will ensure the authenticity of communications sessions when answering requests from the Tanium Server.
1 rule found Severity: Medium

The Tanium Server must protect the confidentiality and integrity of transmitted information with cryptographic signing capabilities enabled to ensure the authenticity of communications sessions when making requests from Tanium Clients.
1 rule found Severity: Medium

2 rules found Severity: Medium

The Tanium cryptographic signing capabilities must be enabled on the Tanium Clients to safeguard the authenticity of communications sessions when answering requests from the Tanium Server.
4 rules found Severity: Medium

4 rules found Severity: Medium

2 rules found Severity: High

Advance package Tool (APT) must be configured to prevent the installation of patches, service packs, device drivers, or Ubuntu operating system components without verification they have been digitally signed using a certificate that is recognized and approved by the organization.
1 rule found Severity: Medium

The Red Hat Enterprise Linux operating system must prevent the installation of software, patches, service packs, device drivers, or operating system components from a repository without verification they have been digitally signed using a certificate that is issued by a Certificate Authority (CA) that is recognized and approved by the organization.
1 rule found Severity: High

The Red Hat Enterprise Linux operating system must prevent the installation of software, patches, service packs, device drivers, or operating system components of local packages without verification they have been digitally signed using a certificate that is issued by a Certificate Authority (CA) that is recognized and approved by the organization.
1 rule found Severity: High

The Red Hat Enterprise Linux operating system must be configured so that the cryptographic hash of system files and commands matches vendor values.
1 rule found Severity: High

The Red Hat Enterprise Linux operating system must ensure cryptographic verification of vendor software packages.
1 rule found Severity: Medium

The Ubuntu operating system's Advance Package Tool (APT) must be configured to prevent the installation of patches, service packs, device drivers, or Ubuntu operating system components without verification they have been digitally signed using a certificate that is recognized and approved by the organization.
1 rule found Severity: Medium

The F5 BIG-IP appliance must be configured to prevent the installation of patches, service packs, or application components without verification the software component has been digitally signed using a certificate that is recognized and approved by the organization.
1 rule found Severity: Medium

The Oracle Linux operating system must be configured so that the cryptographic hash of system files and commands matches vendor values.
1 rule found Severity: High

The Oracle Linux operating system must prevent the installation of software, patches, service packs, device drivers, or operating system components from a repository without verification they have been digitally signed using a certificate that is issued by a Certificate Authority (CA) that is recognized and approved by the organization.
1 rule found Severity: High

The Oracle Linux operating system must prevent the installation of software, patches, service packs, device drivers, or operating system components of local packages without verification they have been digitally signed using a certificate that is issued by a Certificate Authority (CA) that is recognized and approved by the organization.
1 rule found Severity: High

The Oracle Linux operating system must ensure cryptographic verification of vendor software packages.
1 rule found Severity: Medium

All Automation Controller NGINX front-end web server files must be verified for their integrity (e.g., checksums and hashes) before becoming part of the production web server.
1 rule found Severity: High

Expansion modules must be fully reviewed, tested, and signed before they can exist on a production Automation Controller NGINX front-end web server.
1 rule found Severity: Medium

1 rule found Severity: Medium

Expansion modules must be fully reviewed, tested, and signed before they can exist on a production Apache web server.
1 rule found Severity: Medium

1 rule found Severity: High

Ubuntu 22.04 LTS must be configured so that the Advance Package Tool (APT) prevents the installation of patches, service packs, device drivers, or operating system components without verification they have been digitally signed using a certificate that is recognized and approved by the organization.
1 rule found Severity: Low

The application must have the capability to prevent the installation of patches, service packs, or application components without verification the software component has been digitally signed using a certificate that is recognized and approved by the organization.
1 rule found Severity: Medium

Forescout must prevent the installation of patches, service packs, plug-ins, or modules without verification the update has been digitally signed using a certificate that is recognized and approved by the organization.
1 rule found Severity: Low

1 rule found Severity: Medium

Trust Bar notifications must be configured to display information in the Message Bar about the content that has been automatically blocked.
1 rule found Severity: Medium

1 rule found Severity: Medium

1 rule found Severity: Medium

1 rule found Severity: Medium

1 rule found Severity: Medium

1 rule found Severity: Medium

1 rule found Severity: Medium

YUM must be configured to prevent the installation of patches, service packs, device drivers, or OL 8 system components that have not been digitally signed using a certificate that is recognized and approved by the organization.
1 rule found Severity: High

OL 8 must prevent the installation of software, patches, service packs, device drivers, or operating system components of local packages without verification they have been digitally signed using a certificate that is issued by a Certificate Authority (CA) that is recognized and approved by the organization.
1 rule found Severity: High

RHEL 8 must prevent the installation of software, patches, service packs, device drivers, or operating system components from a repository without verification they have been digitally signed using a certificate that is issued by a Certificate Authority (CA) that is recognized and approved by the organization.
1 rule found Severity: High

RHEL 8 must prevent the installation of software, patches, service packs, device drivers, or operating system components of local packages without verification they have been digitally signed using a certificate that is issued by a Certificate Authority (CA) that is recognized and approved by the organization.
1 rule found Severity: High

1 rule found Severity: Medium

1 rule found Severity: Medium

RHEL 9 must check the GPG signature of software packages originating from external software repositories before installation.
1 rule found Severity: High

1 rule found Severity: High

1 rule found Severity: High

1 rule found Severity: Medium

1 rule found Severity: High

1 rule found Severity: Medium

1 rule found Severity: Medium

1 rule found Severity: Medium

2 rules found Severity: High

1 rule found Severity: Medium

The Photon operating system RPM package management tool must cryptographically verify the authenticity of all software packages during installation.
1 rule found Severity: Medium

The Photon operating system RPM package management tool must cryptographically verify the authenticity of all software packages during installation.
1 rule found Severity: Medium

The Photon operating system YUM repository must cryptographically verify the authenticity of all software packages during installation.
1 rule found Severity: Medium

1 rule found Severity: Medium

The Photon operating system TDNF package management tool must cryptographically verify the authenticity of all software packages during installation.
1 rule found Severity: High
