Annex I, Part II, (7)
Mapped SPARTA techniques (6)
Techniques referencing this article
Secure update-distribution mechanisms protect boot-stage code paths; the same provenance and integrity requirements that protect runtime updates apply to boot-image updates.
Secure update-distribution mechanisms protect boot-stage code paths: the same provenance and integrity requirements that protect runtime updates apply to boot-image updates.
Manufacturer obligation to provide secure update-distribution mechanisms is the direct defense against altered/swapped binaries: signed, integrity-verified update channels resist signed-binary swap and update-metadata subversion.
Manufacturer obligation to provide secure update-distribution mechanisms is precisely the defense against on-orbit update pipeline manipulation: signed, integrity-verified update channels resist source-tree manipulation, build-step subversion and packaging tampering.
Secure update-distribution mechanisms protect modifications to memory regions whose integrity is critical (boot, FDIR, persistent configuration).
Manufacturer obligation to provide secure update-distribution mechanisms ensures that remediation actually reaches deployed products; without that distribution path, vulnerability-handling discipline upstream cannot close the exploit window the adversary's recon attempts to widen.