SV-234220r984089_rule
V-234220
SRG-APP-000131-NDM-000243
FGFW-ND-000305
CAT II
10
Administrators can download software directly from a FortiGuard or FortiManager server. These servers are authenticated using digital certificates that ensure identity and non-repudiation of the source packages. This is a preferred method of applying updates.
The Administrator can also download the software from Fortinet's support website portal. The website includes a file checksum to verify file integrity prior to uploading.
Develop a process to download the update files from the Fortinet website, and manually compare the download hash to the hash value provided on the vendor site before applying the update files to the system.
Verify the process used to apply updates and patches to the system.
If the system is updated via a FortiGuard or FortiManager server, those solutions meet the requirement and this is NOT a finding.
If the system is not using a FortiGuard or FortiManager server, and a process is not defined to manually verify the update hash value with the vendor site, this is a finding.
V-234220
False
FGFW-ND-000305
Verify the process used to apply updates and patches to the system.
If the system is updated via a FortiGuard or FortiManager server, those solutions meet the requirement and this is NOT a finding.
If the system is not using a FortiGuard or FortiManager server, and a process is not defined to manually verify the update hash value with the vendor site, this is a finding.
M
5260