NASA Best Practices Guide for Mission Cybersecurity
GR-INTG-01

Software and Firmware Integrity Verification Function

Parent: GR

Description

• The mission should require developers of information systems, system components, or information system services to enable integrity verification of software and firmware components prior to delivery and during mission operations • Each system operated by the mission should provide the capability to verify the integrity of mission-defined software, firmware, and information • The mission should p

Mapped SPARTA techniques

4 techniques

  • IA-0001Compromise Supply ChainST0003
    addresses
    moderate

    The parent supply-chain technique spans source tampering, dependency substitution, update-metadata subversion, and hardware modification. Integrity verification of the delivered software and firmware covers the delivered-artifact face only.

  • IA-0001.02Software Supply ChainST0003
    addresses
    moderate

    The practice requires developers to enable integrity verification of software and firmware, which is the check that detects a build artifact altered anywhere between the developer and the mission. [Curation] Same reasoning as the MI-MALW-01 downgrade. Integrity verification detects alteration of an artifact after the developer signs it, but a supply chain subverted at source produces an artifact whose integrity verifies correctly. One vector covered, dominant scope not.

  • IA-0001.03Hardware Supply ChainST0003
    addresses
    moderate

    Hardware supply chain compromise may present as altered firmware, which the practice covers, or as a physical modification, which it does not. Partial scope coverage caps this at addresses.

  • An on-orbit update compromised in transit is caught by the integrity verification the practice requires developers to enable, which is the same interdiction MI-MALW-01 provides at the malware-validation gate by a different mechanism.

Cite as SafeMode Space, nasa-bpg GR-INTG-01.

Built 2026-07-25 from 216 techniques, 334 regulation articles, 125 ENISA controls, 2,610 framework controls, and 90 countermeasures.