SV-283767r1223369_rule
V-283767
SRG-APP-000131-NDM-000243
NOKI-ND-000310
CAT II
10
Configure the Nokia router to prevent the installation of patches, service packs, or application components without verification the software component has been digitally signed using a certificate that is recognized and approved by the organization.
Activate secure boot on control card "A" and/or card "B" (card B for redundant control systems):
- admin system security secure-boot activate card "A" serial-number <CPM card A serial number> confirmation-code <code>
Determine if the Nokia router prevents the installation of patches, service packs, or application components without verification the software component has been digitally signed using a certificate that is recognized and approved by the organization. This requirement may be verified by demonstration, configuration review, or validated test results.
Verify secure boot is enabled for Control card "A" and/or card "B" (card B for redundant control systems):
- show card "A" detail | match "Secure boot"
Secure boot status : enabled
If the Nokia router does not prevent the installation of patches, service packs, or application components without verification the software component has been digitally signed using a certificate that is recognized and approved by the organization, this is a finding.
V-283767
False
NOKI-ND-000310
Determine if the Nokia router prevents the installation of patches, service packs, or application components without verification the software component has been digitally signed using a certificate that is recognized and approved by the organization. This requirement may be verified by demonstration, configuration review, or validated test results.
Verify secure boot is enabled for Control card "A" and/or card "B" (card B for redundant control systems):
- show card "A" detail | match "Secure boot"
Secure boot status : enabled
If the Nokia router does not prevent the installation of patches, service packs, or application components without verification the software component has been digitally signed using a certificate that is recognized and approved by the organization, this is a finding.
M
5744