NIST 800-53 Rev. 5

SI-7(12): Software, Firmware, and Information Integrity | Integrity Verification

Control Text:

Require that the integrity of the following user-installed software be verified prior to execution: [Assignment: organization-defined user-installed software].

Organizations verify the integrity of user-installed software prior to execution to reduce the likelihood of executing malicious code or programs that contains errors from unauthorized modifications. Organizations consider the practicality of approaches to verifying software integrity, including the availability of trustworthy checksums from software developers and vendors.

Related Controls