Provision of a Mechanism for Verifying Software Release Integrity, v1.1

Specifies requirements in accordance with NIST Secure Software Development Framework (SSDF), version 1.1, Practice PS.2: Provision of a Mechanism for Verifying Software Release Integrity. Requires an organization to help software acquirers ensure that the software they acquire is legitimate and has not been tampered with.

Assessment Step

1
Availability of Software Integrity Verification Data (AvailabilityofSoftwareIntegrityVerificationData)
Does the organization make software integrity verification information available to software acquirers?
Artifact
A1
Provide evidence (e.g. organizational policies, procedures, compliance/assessment reports, etc.) and supporting notes as appropriate to support the assessor's response to this assessment step.

Conformance Criteria (1)

Availability of Software Integrity Verification Data
The organization must make software integrity verification information available to software acquirers.
Citation
SSDF
Task PS.2.1