{"catalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","kind":"record","record":{"attributes":{"category":"technical","domain":"Secure Configuration & Change Management","type":"preventive"},"canonicalUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-CONFIG-06","description":"Assess the authenticity and integrity of hardware and software before acquisition and use, sourcing components from trusted suppliers. Verify digital signatures or equivalent integrity evidence on software, firmware, and updates before installation, and block or investigate components that fail verification.","details":{"control_category":"technical","control_type":"preventive","domain":"Secure Configuration & Change Management","guidance":[],"members":[{"control_id":"CM-14","coverage":"full","framework":"nist-800-53","relationship":"superset_of"},{"control_id":"ID.RA-09","coverage":"full","framework":"nist-csf-2","relationship":"superset_of"}],"statement":"Assess the authenticity and integrity of hardware and software before acquisition and use, sourcing components from trusted suppliers. Verify digital signatures or equivalent integrity evidence on software, firmware, and updates before installation, and block or investigate components that fail verification.","title":"Verify authenticity and integrity of hardware and software","unified_id":"UC-CONFIG-06"},"id":"uc:UC-CONFIG-06","mapUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-CONFIG-06","sourceIds":["nist-800-53","nist-csf-2"],"sourceUrl":null,"title":"UC-CONFIG-06 — Verify authenticity and integrity of hardware and software","type":"unified"},"relationships":[{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:124988e2cf6b7833f2dd43b8ea888ec4df7e58583484cb675efdd2decb13400d","properties":{},"sourceDetailPath":"/data/v1/records/wf-c43-e401f9da.json","sourceId":"wf:C43","targetDetailPath":"/data/v1/records/uc-uc-config-06-31f293f7.json","targetId":"uc:UC-CONFIG-06","type":"operates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:64bd2b6072ef52ffe996f0d7e0c4450db0c28d2fb9d45111eba3a2291dc3646e","properties":{"control_id":"ID.RA-09","coverage":"full","delta":null,"framework":"nist-csf-2","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2.0"},"sourceDetailPath":"/data/v1/records/uc-uc-config-06-31f293f7.json","sourceId":"uc:UC-CONFIG-06","targetDetailPath":"/data/v1/records/ctrl-nist-csf-2-id-ra-09-d06b6a36.json","targetId":"ctrl:nist-csf-2:ID.RA-09","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:6e4f9e6ec5ac5bc825e3155264956ed35eb5a080be827d900b0ca440f5dfc8d9","properties":{"rationale":"Authenticity/integrity verification detects counterfeit software components, though license-entitlement tracking is the operative control for that risk.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-config-06-31f293f7.json","sourceId":"uc:UC-CONFIG-06","targetDetailPath":"/data/v1/records/risk-tech-unlicensed-counterfeit-software-91025350.json","targetId":"risk:tech-unlicensed-counterfeit-software","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:9487c3a7d89f92bd94d86812dbfc811c11cc7241f6bb7030c2fde9ad5e92506d","properties":{},"sourceDetailPath":"/data/v1/records/wf-c9-75fb1752.json","sourceId":"wf:C9","targetDetailPath":"/data/v1/records/uc-uc-config-06-31f293f7.json","targetId":"uc:UC-CONFIG-06","type":"tests"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:bfe844ecfbcdc47bce29a95ee1844b0b24dd01c513f4494033f5812b8dea014c","properties":{"rationale":"Verifying digital signatures/integrity and sourcing from trusted suppliers before use directly blocks tampered or counterfeit hardware and software from entering.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-config-06-31f293f7.json","sourceId":"uc:UC-CONFIG-06","targetDetailPath":"/data/v1/records/risk-tprm-supply-chain-injection-ad1f5937.json","targetId":"risk:tprm-supply-chain-injection","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:f9b6574049a8871d046cf6854d785cb6baf1e72ff41e7206fc5b9b3e17a9a3cd","properties":{"control_id":"CM-14","coverage":"full","delta":null,"framework":"nist-800-53","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"Rev. 5"},"sourceDetailPath":"/data/v1/records/uc-uc-config-06-31f293f7.json","sourceId":"uc:UC-CONFIG-06","targetDetailPath":"/data/v1/records/ctrl-nist-800-53-cm-14-64650a51.json","targetId":"ctrl:nist-800-53:CM-14","type":"maps_to"}],"schemaVersion":1}
