CCI-003992
Prevent the installation of organization-defined software and firmware components without verification that the component has been digitally signed using a certificate that is recognized and approved by the organization.
The Ubuntu operating system's Advance Package Tool (APT) must be configured to prevent the installation of patches, service packs, device drivers, or Ubuntu operating system components without verification they have been digitally signed using a certificate that is recognized and approved by the organization.
1 rule found Severity: Medium

The DNS server implementation must prevent the installation of organization-defined software and firmware components without verification that the component has been digitally signed using a certificate that is recognized and approved by the organization.
1 rule found Severity: Medium

A private web server must subscribe to certificates, issued from any DOD-authorized Certificate Authority (CA), as an access control mechanism for web users.
1 rule found Severity: Medium

The network device must prevent the installation of patches, service packs, or application components without verification the software component has been digitally signed using a certificate that is recognized and approved by the organization.
1 rule found Severity: Medium

The Oracle Linux operating system must be configured so that the cryptographic hash of system files and commands matches vendor values.
1 rule found Severity: High

The Oracle Linux operating system must prevent the installation of software, patches, service packs, device drivers, or operating system components from a repository without verification they have been digitally signed using a certificate that is issued by a Certificate Authority (CA) that is recognized and approved by the organization.
1 rule found Severity: High

The Oracle Linux operating system must prevent the installation of software, patches, service packs, device drivers, or operating system components of local packages without verification they have been digitally signed using a certificate that is issued by a Certificate Authority (CA) that is recognized and approved by the organization.
1 rule found Severity: High

The Oracle Linux operating system must ensure cryptographic verification of vendor software packages.
1 rule found Severity: Medium

All Automation Controller NGINX front-end web server files must be verified for their integrity (e.g., checksums and hashes) before becoming part of the production web server.
1 rule found Severity: High

Expansion modules must be fully reviewed, tested, and signed before they can exist on a production Automation Controller NGINX front-end web server.
1 rule found Severity: Medium

The Tanium cryptographic signing capabilities must be enabled on the Tanium Clients to safeguard the authenticity of communications sessions when answering requests from the Tanium Server.
2 rules found Severity: Medium

2 rules found Severity: Medium

1 rule found Severity: Medium

TOSS must prevent the installation of patches, service packs, device drivers, or operating system components without verification they have been digitally signed using a certificate that is recognized and approved by the organization.
1 rule found Severity: High

All web server files must be verified for their integrity (e.g., checksums and hashes) before becoming part of the production web server.
1 rule found Severity: Medium

Expansion modules must be fully reviewed, tested, and signed before they can exist on a production web server.
1 rule found Severity: Medium

NixOS must prevent the installation of patches, service packs, device drivers, or operating system components without verification they have been digitally signed using a certificate that is recognized and approved by the organization.
1 rule found Severity: High

Expansion modules must be fully reviewed, tested, and signed before they can exist on a production Apache web server.
1 rule found Severity: Medium

2 rules found Severity: High

The application server must prevent the installation of patches, service packs, or application components without verification the software component has been digitally signed using a certificate recognized and approved by the organization.
1 rule found Severity: Medium

Ubuntu 22.04 LTS must be configured so that the Advance Package Tool (APT) prevents the installation of patches, service packs, device drivers, or operating system components without verification they have been digitally signed using a certificate that is recognized and approved by the organization.
1 rule found Severity: Low

The application must have the capability to prevent the installation of patches, service packs, or application components without verification the software component has been digitally signed using a certificate that is recognized and approved by the organization.
1 rule found Severity: Medium

The Central Log Server must prevent the installation of organization-defined software and firmware components without verification that the component has been digitally signed using a certificate that is recognized and approved by the organization.
1 rule found Severity: Medium

AlmaLinux OS 9 must check the GPG signature of software packages originating from external software repositories before installation.
1 rule found Severity: High

1 rule found Severity: High

AlmaLinux OS 9 must check the GPG signature of locally installed software packages before installation.
1 rule found Severity: High

1 rule found Severity: High

1 rule found Severity: High

1 rule found Severity: Medium

The Dell OS10 Switch must prevent the installation of patches, service packs, or application components without verification the software component has been digitally signed using a certificate that is recognized and approved by the organization.
1 rule found Severity: Medium

The DBMS must prevent the installation of organization-defined software and firmware components without verification that the component has been digitally signed using a certificate recognized and approved by the organization.
1 rule found Severity: Medium

Forescout must prevent the installation of patches, service packs, plug-ins, or modules without verification the update has been digitally signed using a certificate that is recognized and approved by the organization.
1 rule found Severity: Low

The operating system must prevent the installation of patches, service packs, device drivers, or operating system components without verification they have been digitally signed using a certificate that is recognized and approved by the organization.
1 rule found Severity: High

The HYCU virtual appliance must prevent the installation of patches, service packs, or application components without verification the software component has been digitally signed using a certificate that is recognized and approved by the organization.
1 rule found Severity: Medium

The Mainframe Product must prevent the installation of patches, service packs, or application components without verification that the software component has been digitally signed using a certificate that is recognized and approved by the organization.
1 rule found Severity: Medium

1 rule found Severity: Medium

Trust Bar notifications must be configured to display information in the Message Bar about the content that has been automatically blocked.
1 rule found Severity: Medium

1 rule found Severity: Medium

1 rule found Severity: Medium

1 rule found Severity: Medium

1 rule found Severity: Medium

1 rule found Severity: Medium

1 rule found Severity: Medium

YUM must be configured to prevent the installation of patches, service packs, device drivers, or OL 8 system components that have not been digitally signed using a certificate that is recognized and approved by the organization.
1 rule found Severity: High

OL 8 must prevent the installation of software, patches, service packs, device drivers, or operating system components of local packages without verification they have been digitally signed using a certificate that is issued by a Certificate Authority (CA) that is recognized and approved by the organization.
1 rule found Severity: High

RHEL 8 must prevent the installation of software, patches, service packs, device drivers, or operating system components from a repository without verification they have been digitally signed using a certificate that is issued by a Certificate Authority (CA) that is recognized and approved by the organization.
1 rule found Severity: High

RHEL 8 must prevent the installation of software, patches, service packs, device drivers, or operating system components of local packages without verification they have been digitally signed using a certificate that is issued by a Certificate Authority (CA) that is recognized and approved by the organization.
1 rule found Severity: High

1 rule found Severity: Medium

1 rule found Severity: Medium

RHEL 9 must check the GPG signature of software packages originating from external software repositories before installation.
1 rule found Severity: High

1 rule found Severity: High

1 rule found Severity: High

1 rule found Severity: Medium

The UEM server must prevent the installation of patches, service packs, or application components without verification the software component has been digitally signed using a certificate that is recognized and approved by the organization.
1 rule found Severity: Medium

The VMM must prevent the installation of guest VMs, patches, service packs, device drivers, or VMM components without verification they have been digitally signed using a certificate that is recognized and approved by the organization.
1 rule found Severity: Medium

1 rule found Severity: High

The Photon operating system TDNF package management tool must cryptographically verify the authenticity of all software packages during installation.
1 rule found Severity: High
