This is a potential security issue, you are being redirected to https://nvd.nist.gov
Search & Statistics
CVSS V3 Calculator
CVSS V2 Calculator
Checklist (NCP) Repository
SCAP Validated Tools
Security and Privacy Controls for Federal Information Systems and Organizations
Revision 4 Statements
Loads and executes the operating environment from hardware-enforced, read-only media; and
Loads and executes [Assignment: organization-defined applications] from hardware-enforced, read-only media.
The term operating environment is defined as the specific code that hosts applications, for example, operating systems, executives, or monitors including virtual machine monitors (i.e., hypervisors). It can also include certain applications running directly on hardware platforms. Hardware-enforced, read-only media include, for example, Compact Disk-Recordable (CD-R)/Digital Video Disk-Recordable (DVD-R) disk drives and one-time programmable read-only memory. The use of non-modifiable storage ensures the integrity of software from the point of creation of the read-only image. The use of reprogrammable read-only memory can be accepted as read-only media provided: (i) integrity can be adequately protected from the point of initial writing to the insertion of the memory into the information system; and (ii) there are reliable hardware protections against reprogramming the memory while installed in organizational information systems.
Related to: AC-3, SI-7
Employs hardware-based, write-protect for [Assignment: organization-defined information system firmware components]; and
Implements specific procedures for [Assignment: organization-defined authorized individuals] to manually disable hardware write-protect for firmware modifications and re-enable the write-protect prior to returning to operational mode.