ISC2 CISSP (Certified Information Systems Security Professional)Security Architecture and EngineeringMedium
A security architect is evaluating a new manufacturing control system that utilizes embedded devices. The architect discovers that critical firmware updates are delivered over an unencrypted channel without any integrity checks. This vulnerability could allow an attacker to install malicious firmware. Which security principle is primarily violated in this scenario?
- ADefense in Depth
- BSecure Defaults
- CSecure Updates
- DLeast Privilege
Show answer & explanationAnswer & explanation
Correct answer: C. Secure Updates
The scenario describes a compromised firmware update process due to a lack of encryption and integrity checks. This directly violates the principle of Secure Updates, which mandates that updates should be delivered securely (e.g., encrypted, signed) to prevent tampering and ensure authenticity.
Why the other options are wrong
- A. Defense in Depth is about layering security controls, but 'Secure Updates' is a more specific principle violated here.
- B. Secure Defaults refers to shipping products with secure configurations out-of-the-box, which is related but not the direct violation of the update mechanism.
- D. Least Privilege concerns giving subjects only the necessary permissions, not the update mechanism itself.
Secure Updates
A security principle emphasizing that software and firmware updates must be delivered and installed securely, ensuring authenticity and integrity.
- Updates should be cryptographically signed by a trusted entity.
- Updates should be delivered over encrypted channels.
- Prevents tampering and installation of malicious code.
Memory trick: Updates Must Be Signed for Security.