STIGQter STIGQter: STIG Summary: Nokia Service Router OS 25.x Network Device Management Security Technical Implementation Guide Version: 1 Release: 1 Benchmark Date: 28 Apr 2026:

The Nokia router must prevent the installation of patches, service packs, or application components without verification the software component has been digitally signed using a certificate that is recognized and approved by the organization.

DISA Rule

SV-283767r1223369_rule

Vulnerability Number

V-283767

Group Title

SRG-APP-000131-NDM-000243

Rule Version

NOKI-ND-000310

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure the Nokia router to prevent the installation of patches, service packs, or application components without verification the software component has been digitally signed using a certificate that is recognized and approved by the organization.

Activate secure boot on control card "A" and/or card "B" (card B for redundant control systems):

- admin system security secure-boot activate card "A" serial-number <CPM card A serial number> confirmation-code <code>

Check Contents

Determine if the Nokia router prevents the installation of patches, service packs, or application components without verification the software component has been digitally signed using a certificate that is recognized and approved by the organization. This requirement may be verified by demonstration, configuration review, or validated test results.

Verify secure boot is enabled for Control card "A" and/or card "B" (card B for redundant control systems):

- show card "A" detail | match "Secure boot"
Secure boot status : enabled

If the Nokia router does not prevent the installation of patches, service packs, or application components without verification the software component has been digitally signed using a certificate that is recognized and approved by the organization, this is a finding.

Vulnerability Number

V-283767

Documentable

False

Rule Version

NOKI-ND-000310

Severity Override Guidance

Determine if the Nokia router prevents the installation of patches, service packs, or application components without verification the software component has been digitally signed using a certificate that is recognized and approved by the organization. This requirement may be verified by demonstration, configuration review, or validated test results.

Verify secure boot is enabled for Control card "A" and/or card "B" (card B for redundant control systems):

- show card "A" detail | match "Secure boot"
Secure boot status : enabled

If the Nokia router does not prevent the installation of patches, service packs, or application components without verification the software component has been digitally signed using a certificate that is recognized and approved by the organization, this is a finding.

Check Content Reference

M

Target Key

5744