STIGhubSTIGhub
STIGsRMF ControlsCompare
STIGhub— A free STIG search and compliance tool·STIGs updated 3 days ago
Powered by Pylon·Privacy·Terms·© 2026 Beacon Cloud Solutions, Inc.
← CM-5 (3) — Signed Components

CCI-000351

Definition

The organization defines critical software programs that the information system will prevent from being installed if such software programs are not signed with a recognized and approved certificate.

Parent Control

CM-5 (3)Signed ComponentsConfiguration Management

Linked STIG Checks (1)

V-22588CAT IIIThe system package management tool must cryptographically verify the authenticity of software packages during installation.SUSE Linux Enterprise Server v11 for System z Security Technical Implementation Guide