CCI-002512
CCI-002512 Definition
| Status | |
| Type | CheckType.policy |
Master Assessment Datasheet
Implementation Guidance
Determine if: - specific procedures are implemented for [SC-51_ODP[02]; authorized individuals requiring procedures for disabling and re-enabling hardware write-protect are defined] to manually disable hardware write-protect for firmware modifications. - specific procedures are implemented for [SC-51_ODP[02]; authorized individuals requiring procedures for disabling and re-enabling hardware write-protect are defined] to re-enable the write-protect prior to returning to operational mode.
Validation Procedures
Examine: [SELECT FROM: System and communications protection policy; procedures addressing firmware modifications; system design documentation; system configuration settings and associated documentation; system architecture; system audit records; system security plan; other relevant documents or records]. Interview: [SELECT FROM: System/network administrators; organizational personnel with information security responsibilities; organizational personnel installing, configuring, and/or maintaining the system; system developers/integrators]. Test: [SELECT FROM: Organizational processes for modifying system firmware; mechanisms supporting and/or implementing hardware-based write-protection for system firmware].