Zero Trust Engineering — Hardware and software integrity measurement
securityv1/01 Views
/02 About
Devices and endpoints engineering reference for hardware and software integrity measurement, including policy, logical interfaces, recovery and assurance.
Purpose: Hardware and software integrity measurement. Domain: Devices and endpoints. Family: assurance. Scenario trigger: Measure boot and runtime integrity. Input assurance: Signed boot measurements, software manifest and trusted root. Evaluation: Compare measured state against approved integrity baselines. Governing policy: Trusted boot, configuration and firmware acceptance policy. Resource-side obligation: Publish integrity assessment with bounded freshness. Protected concern: Sensitive endpoint execution environment. Logical interface: Measured boot event firmware hash approved baseline and time. Evidence: Integrity measurement manifest and decision evidence. Failure: Tampered firmware or untrusted measurement origin. Required recovery: Limit access and invoke measured-state repair. Architectural invariant: Claims of software integrity require authenticated measurements and approved baselines Adoption: replace reference roles with concrete owner-controlled services. Specify exact provider/consumer identities, schema fields and classifications, signal provenance and freshness, idempotency, authorization lifetime, timeout/retry limits, observation and tamper evidence. A denied or failed operation must not silently become a permitted one. Scope: original vendor-neutral, implementation-agnostic technical reference model. Illustrative logical components and behaviors are neither a deployed system nor evidence of regulatory compliance. Package identities remain stable within the package; cross-package semantic reconciliation requires separate explicit registry support.
Curated · other · unspecified · Published by Lattix · 29 elements · 33 relationships · validated on publish
/03 Contents
- Capability
- Devices and endpoints, Hardware and software integrity measurement
- Role
- Devices and endpoints owner
- Business Actor
- Security telemetry or evidence producer
- Activity
- Measure boot and runtime integrity, Verify: Signed boot measurements, software manifest and trusted root, Assess: Compare measured state against approved integrity baselines, Execute: Publish integrity assessment with bounded freshness, Exception: Tampered firmware or untrusted measurement origin, Recover: Limit access and invoke measured-state repair, Verify and disposition finding
- Application Component
- Signed boot measurements, software manifest and trusted root, Compare measured state against approved integrity baselines, Publish integrity assessment with bounded freshness, Authenticated observation source, Detection and evidence correlation
- Application
- Sensitive endpoint execution environment
- Policy
- Trusted boot, configuration and firmware acceptance policy
- API
- Hardware and software integrity measurement logical interface
- Message/Event Schema
- Measured boot event firmware hash approved baseline and time
- Data Store
- Integrity measurement manifest and decision evidence, Versioned technical finding
- Control
- Hardware and software integrity measurement enforcement assurance
- Risk
- Tampered firmware or untrusted measurement origin risk
- Requirement
- Claims of software integrity require authenticated measurements and approved baselines
- Measure
- Hardware and software integrity measurement assurance completeness
- Trust Boundary
- Hardware and software integrity measurement authority boundary
- State
- Control condition verified, Control gap or untrusted signal