CCI-002602
CCI-002602 Definition
Status | |
Type | CheckType.policy |
Master Assessment Datasheet
Implementation Guidance
The organization being inspected/assessed documents and implements a process to test firmware updates related to flaw remediation for effectiveness before installation. If the firmware update is being provided by a vendor who has documented the effectiveness of the update in fixing the affected IAVM/CVE, further testing by the organization may not be required.
Validation Procedures
The organization conducting the inspection/assessment obtains and examines the documented process and test results to ensure the organization being inspected/assessed tests firmware updates related to flaw remediation for effectiveness before installation.
Compelling Evidence
1.) Signed and dated system security plan. 2.) Continuous monitoring plan. 3.) Reference to system security plan and continuous monitoring plan sections pertaining to the process for testing firmware updates. 4.) Signed and dated testing process logs.