# CM-14 Signed Components

NIST SP 800-53 control. Family: CM Configuration Management. Function: preventative. In no baseline. Mapping licence: CC BY-SA 4.0.

Statement: Prevent the installation of [Assignment: organization-defined software and firmware components] without verification that the component has been digitally signed using a certificate that is recognized and approved by the organization.
Guidance: Software and firmware components prevented from installation unless signed with recognized and approved certificates include software and firmware version updates, patches, service packs, device drivers, and basic input/output system updates. Organizations can identify applicable software and firmware components by type, by specific items, or a combination of both. Digital signatures and organizational verification of such signatures is a method of code authentication.

## Patterns that use it (3)
- Critical (2): SP-028 Secure DevOps Pipeline Pattern; SP-050 Mobile Security Architecture (draft)
- Important (1): SP-040 Post-Quantum Cryptography and Quantum Readiness

## Clauses by framework (52 frameworks)
- iso_27001_2022: A.8.9, A.8.19. OSA's own, not in NIST's crosswalk: A.8.9, A.8.19
- iso_27002_2022: 8.9, 8.19
- cobit_2019: BAI06, BAI10, DSS05
- pci_dss_v4: 6.2, 11.5, 11.6
- nist_csf_2: PR.PS-05. OSA's own, not in NIST's crosswalk: PR.PS-05
- cis_controls_v8: CIS 2, CIS 2.6
- finos_ccc: CCC-C07
- iso_42001_2023: A.7.5
- iec_62443: 3-3 SR 3.1, 3-3 SR 3.4
- asd_e8: E8-1, E8-1 ML3, E8-3 ML3
- nis2: Art. 21(2)(e)
- mas_trm: 6
- bsi_grundschutz: NET.3.1, OPS.1.1.3, SYS.1.1
- anssi: Hygiene.18, Hygiene.20, Hygiene.33, Hygiene.34, SecNumCloud.13.1, SecNumCloud.13.2, SecNumCloud.15.4
- osfi_b13: B-13.2.2, B-13.2.3
- finma_circular: IV.A(36), IV.A(37), IV.A(39), IV.C(64), V(109), V(110)
- dora: Art.9(4)(e)
- bio2: 8.9, 8.19
- rbi_csf: Annex1.2, Annex1.6
- fisc: FISC.O3, FISC.T6
- hkma_tme1: TME1.3.2, TME1.4.1, TME1.4.3
- cbb_tm: TM-7
- cbuae: CR-6
- nca_ecc: 2-3
- qatar_nia: OS, SD
- sama_csf: 3.2, 3.5
- uae_ia: T7, T10
- bog_cisd: CISD-SDLC
- bom_ctrm: 3.6, 3.11
- cbe_csf: CTO-4
- sa_js2: JS2-SA
- bot_cyber: Ch2.1
- eba_ict: 3.6.3
- ecb_croe: CROE.2.3.4
- ffiec_is: II.C.17
- iosco_cyber: PROT-6
- sebi_cscrf: PR.ES, PR.IP
- cmmc_2: CM
- nerc_cip: CIP-013-2
- nrc_73_54: RG5.71-A-SI, RG5.71-C-SR
- ieee_1686: 5.3
- ferc_cip: Order 829
- api_1164: Sec 7
- iaea_nss: Sec 5.4
- pci_pts: B, F
- fips_140: FIPS 140-3 §7.5
- common_criteria: CC Part 2 — FCS, CC Part 2 — FPT
- fca_sysc_13: SYSC 13.7.4
- lloyds_ms: MS8.4
- solvency_ii: EIOPA-ICT-4.8, EIOPA-ICT-4.11
- owasp_masvs_v2: MASVS-RESILIENCE-1, MASVS-RESILIENCE-2
- bssc: NOS-02
OSA's mapping for iso_27001_2022 and nist_csf_2 takes NIST's published crosswalk as its base. A clause not marked as OSA's own is in that crosswalk.

## More
- This control as JSON, with guidance and ATT&CK techniques: /api/v1/controls/CM-14
- Clauses only: /api/v1/controls/CM-14?fields=mappings
- Page for people: /controls/cm-14/
- Found an error? Open an issue at https://github.com/opensecurityarchitecture/osa-data/issues with the id, what OSA says and what the source says.
