Provision of a Mechanism for Verifying Software Release Integrity, v1.1
Specifies requirements in accordance with NIST Secure Software Development Framework (SSDF), version 1.1, Practice PS.2: Provision of a Mechanism for Verifying Software Release Integrity. Requires an organization to help software acquirers ensure that the software they acquire is legitimate and has not been tampered with.
Assessment Step
1
Availability of Software Integrity Verification Data (AvailabilityofSoftwareIntegrityVerificationData)
Does the organization make software integrity verification information available to software acquirers?
Artifact
A1
Provide evidence (e.g. organizational policies, procedures, compliance/assessment reports, etc.) and supporting notes as appropriate to support the assessor's response to this assessment step.
|
Conformance Criteria (1)
Availability of Software Integrity Verification Data
The organization must make software integrity verification information available to software acquirers.
Citation
SSDF
Task PS.2.1
|