ISC2 CISSP (Certified Information Systems Security Professional)Security Architecture and EngineeringMedium

A security architect is evaluating a new embedded system designed for industrial control. The system needs to guarantee the integrity of its operating system and firmware from unauthorized modification throughout its lifecycle, even during boot-up. Which security capability is most crucial for achieving this requirement?

  1. AAdvanced Encryption Standard (AES) for data at rest.
  2. BSecure Sockets Layer (SSL) for remote management access.
  3. CTrusted Platform Module (TPM) for secure boot and integrity measurement.
  4. DRole-Based Access Control (RBAC) for managing user permissions.
Show answer & explanation

Correct answer: C. Trusted Platform Module (TPM) for secure boot and integrity measurement.

A Trusted Platform Module (TPM) is specifically designed to provide hardware-based security functions, including secure boot, integrity measurements, and cryptographic operations. It ensures that the system boots into a trusted state and that the operating system and firmware have not been tampered with.

Why the other options are wrong

  • A. AES encrypts data, but doesn't guarantee the integrity of the OS/firmware itself during boot.
  • B. SSL secures communication channels but doesn't protect the integrity of the underlying system components.
  • D. RBAC manages user authorization within an operating system, not the integrity of the OS or firmware during boot.

Trusted Platform Module (TPM)

A secure cryptoprocessor that stores cryptographic keys, measures boot integrity, and provides other hardware-based security functions.

  • Provides a hardware root of trust for platforms.
  • Used for secure boot, disk encryption (e.g., BitLocker), and digital rights management.
  • Protects against software attacks by ensuring system integrity from boot-up.

Memory trick: For embedded systems, TPM is the guardian of the boot.

More Security Architecture and Engineering questions