unified
UC-CONFIG-06 — Verify authenticity and integrity of hardware and software
Assess the authenticity and integrity of hardware and software before acquisition and use, sourcing components from trusted suppliers. Verify digital signatures or equivalent integrity evidence on software, firmware, and updates before installation, and block or investigate components that fail verification.
Record JSON · Open in map · Data retrieval guide
Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.
Attributes
- domain
- Secure Configuration & Change Management
- type
- preventive
- category
- technical
Details
- unified_id
- UC-CONFIG-06
- title
- Verify authenticity and integrity of hardware and software
- statement
- Assess the authenticity and integrity of hardware and software before acquisition and use, sourcing components from trusted suppliers. Verify digital signatures or equivalent integrity evidence on software, firmware, and updates before installation, and block or investigate components that fail verification.
- domain
- Secure Configuration & Change Management
- control_type
- preventive
- control_category
- technical
- members
- framework
- nist-800-53
- control_id
- CM-14
- coverage
- full
- relationship
- superset_of
- framework
- nist-csf-2
- control_id
- ID.RA-09
- coverage
- full
- relationship
- superset_of
- guidance
Source
No record-specific source URL is provided.
Connections
- Authorized Software & Component Integrity Control operates UC-CONFIG-06 — Verify authenticity and integrity of hardware and software
- UC-CONFIG-06 — Verify authenticity and integrity of hardware and software maps_to ID.RA-09 — Risk Assessment: The authenticity and integrity of hardware and software are assessed prior to acquisition and use
- framework
- nist-csf-2
- control_id
- ID.RA-09
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- 2.0
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- UC-CONFIG-06 — Verify authenticity and integrity of hardware and software mitigates Use of unlicensed, counterfeit or pirated software
- strength
- related
- rationale
- Authenticity/integrity verification detects counterfeit software components, though license-entitlement tracking is the operative control for that risk.
- Security Control Assessment & POA&M Remediation tests UC-CONFIG-06 — Verify authenticity and integrity of hardware and software
- UC-CONFIG-06 — Verify authenticity and integrity of hardware and software mitigates Malicious supply-chain injection of tampered hardware/software
- strength
- primary
- rationale
- Verifying digital signatures/integrity and sourcing from trusted suppliers before use directly blocks tampered or counterfeit hardware and software from entering.
- UC-CONFIG-06 — Verify authenticity and integrity of hardware and software maps_to CM-14 — Signed Components
- framework
- nist-800-53
- control_id
- CM-14
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- Rev. 5
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.