1.3.2 Ensure 'Image Authenticity' is correct

Information

Verifies for digitally signed images that the running image is from a trusted source

Rationale:

The software image being a code can be vulnerable to many attacks such as malicious code injection in the software, the modification of the code installed in the ROM. In order to ensure that the image running is from a trusted source, the image is digitally signed and its certificate should be verified.

Solution

Step 1: Correct the errors on the hardware and software

Step 2: Run the audit procedure until the system is compliant

Step 3: Implement secure delivery of hardware and harden the software distribution server

See Also

https://workbench.cisecurity.org/benchmarks/7194