Finding ID | Version | Rule ID | IA Controls | Severity |
---|---|---|---|---|
V-33248 | SRG-OS-000237-MOS-000125 | SV-43666r1_rule | Medium |
Description |
---|
Digital signatures enable the system to verify the integrity of the signed object and authenticate the object's signatory. Failure to maintain the binding of digital signatures on software components and applications in process makes it more likely that an adversary could modify or replace those objects when the software is executed. The bindings enable the operating system to verify the software's integrity and source just before the execution process. |
STIG | Date |
---|---|
Mobile Operating System Security Requirements Guide | 2012-10-01 |
Check Text ( C-41544r1_chk ) |
---|
Review the mobile operating system configuration for maintaining binding of digital signatures to software objects when those objects are in process. If these bindings are not maintained during processing, this is a finding. |
Fix Text (F-37178r1_fix) |
---|
Configure the operating system to maintain the binding of digital signatures on software components and applications in process. |