Under active development Content is continuously updated and improved

SI-7(13)Software, Firmware, And Information Integrity

Operational

>Control Description

SOFTWARE, FIRMWARE, AND INFORMATION INTEGRITY | CODE EXECUTION IN PROTECTED ENVIRONMENTS The organization allows execution of binary or machine-executable code obtained from sources with limited or no warranty and without the provision of source code only in confined physical or virtual machine environments and with the explicit approval of organization-defined personnel or roles.

>Supplemental Guidance

This control enhancement applies to all sources of binary or machine-executable code including, for example, commercial software/firmware and open source software.

Ask AI

Configure your API key to use AI features.