Back to catalog
CFG-09.2CFGConfiguration Management
Software Repository Protections
Description
Mechanisms exist to protect software repositories from importing untrusted and/or malicious software artifacts by: (1) Scanning artifacts for malicious content; (2) Verifying a digital signature or secure hash provided over a secure channel; and (3) Scanning artifacts to identify plain text or encoded secrets and keys.
SCF
Powered by the Secure Controls Framework
The control catalog, cross-mappings, and STRM relationship data shown here are provided by the Secure Controls Framework (SCF), 2026.2. Every mapping is credited to SCF as the methodology, with the SCF reference and version stored alongside it.
© SCF Council, LLC. Secure Controls Framework content is free and shown here with attribution. securecontrolsframework.com · About SCF on STIGViewer