Secure Controls Framework

1,534 controls across 34 domains

Source: SCF 2026.2About SCF
securecontrolsframework.com
Back to catalog
CHG-04.2CHGChange Management

Signed Components

Description

Mechanisms exist to prevent the installation of software and firmware components without verification that the component has been digitally signed using an organization-approved certificate authority.

Cross-Mappings

157 paths across 3 frameworks
NIST 800-532 mappings
CM-14
0.50
  • Secure Controls Framework · 2026.2 · scf_strm · related
  • Secure Controls Framework · 2026.2 · scf_strm · related
CCI4 mappings
CCI-002739
0.50
  • Secure Controls Framework · 2026.2 · scf_strm · related
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-002740
0.50
  • Secure Controls Framework · 2026.2 · scf_strm · related
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-003992
0.50
  • Secure Controls Framework · 2026.2 · scf_strm · related
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-003993
0.50
  • Secure Controls Framework · 2026.2 · scf_strm · related
  • DISA · 2025-01-23 · disa_cci_list · equivalent
STIG100 mappings
SV-202047r984089_ruleThe network device must prevent the installation of patches, service packs, or application components without verification the software component has been digitally signed using a certificate that is recognized and approved by the organization.
0.50
  • Secure Controls Framework · 2026.2 · scf_strm · related
  • DISA · 2025-01-23 · disa_cci_list · equivalent
  • DISA · V5R3 · disa_xccdf · related
SV-203720r982212_ruleThe operating system must prevent the installation of patches, service packs, device drivers, or operating system components without verification they have been digitally signed using a certificate that is recognized and approved by the organization.
0.50
  • Secure Controls Framework · 2026.2 · scf_strm · related
  • DISA · 2025-01-23 · disa_cci_list · equivalent
  • DISA · 3 · disa_xccdf · related
SV-204740r981678_ruleThe application server must prevent the installation of patches, service packs, or application components without verification the software component has been digitally signed using a certificate recognized and approved by the organization.
0.50
  • Secure Controls Framework · 2026.2 · scf_strm · related
  • DISA · 2025-01-23 · disa_cci_list · equivalent
  • DISA · 4 · disa_xccdf · related
SV-205483r982281_ruleThe Mainframe Product must prevent the installation of patches, service packs, or application components without verification that the software component has been digitally signed using a certificate that is recognized and approved by the organization.
0.50
  • Secure Controls Framework · 2026.2 · scf_strm · related
  • DISA · 2025-01-23 · disa_cci_list · equivalent
  • DISA · 3 · disa_xccdf · related
SV-206372r984351_ruleAll web server files must be verified for their integrity (e.g., checksums and hashes) before becoming part of the production web server.
0.50
  • Secure Controls Framework · 2026.2 · scf_strm · related
  • DISA · 2025-01-23 · disa_cci_list · equivalent
  • DISA · 4 · disa_xccdf · related
SV-206373r984352_ruleExpansion modules must be fully reviewed, tested, and signed before they can exist on a production web server.
0.50
  • Secure Controls Framework · 2026.2 · scf_strm · related
  • DISA · 2025-01-23 · disa_cci_list · equivalent
  • DISA · 4 · disa_xccdf · related
SV-207472r984242_ruleThe VMM must prevent the installation of guest VMs, patches, service packs, device drivers, or VMM components without verification they have been digitally signed using a certificate that is recognized and approved by the organization.
0.50
  • Secure Controls Framework · 2026.2 · scf_strm · related
  • DISA · 2025-01-23 · disa_cci_list · equivalent
  • DISA · 2 · disa_xccdf · related
SV-214238r1016509_ruleExpansion modules must be fully reviewed, tested, and signed before they can exist on a production Apache web server.
0.50
  • Secure Controls Framework · 2026.2 · scf_strm · related
  • DISA · 2025-01-23 · disa_cci_list · equivalent
  • DISA · 3 · disa_xccdf · related
SV-219969r1016281_ruleThe system must verify that package updates are digitally signed.
0.50
  • Secure Controls Framework · 2026.2 · scf_strm · related
  • DISA · 2025-01-23 · disa_cci_list · equivalent
  • DISA · 3 · disa_xccdf · related
SV-219997r1016296_ruleThe system must verify that package updates are digitally signed.
0.50
  • Secure Controls Framework · 2026.2 · scf_strm · related
  • DISA · 2025-01-23 · disa_cci_list · equivalent
  • DISA · 3 · disa_xccdf · related

+90 more (top 10 by confidence shown)

Control mappings provided by the Secure Controls Framework (SCF).

SCF

Powered by the Secure Controls Framework

The control catalog, cross-mappings, and STRM relationship data shown here are provided by the Secure Controls Framework (SCF), 2026.2. Every mapping is credited to SCF as the methodology, with the SCF reference and version stored alongside it.

© SCF Council, LLC. Secure Controls Framework content is free and shown here with attribution. securecontrolsframework.com · About SCF on STIGViewer