Platform Security (PR.PS)

The hardware, software (e.g., firmware, operating systems, applications), and services of physical and virtual platforms are managed consistent with the organization's risk strategy to protect their confidentiality, integrity, and availability

Subcategories

PR.PS-01

Configuration management practices are established and applied

PR.PS-02

Software is maintained, replaced, and removed commensurate with risk

PR.PS-03

Hardware is maintained, replaced, and removed commensurate with risk

PR.PS-04

Log records are generated and made available for continuous monitoring

PR.PS-05

Installation and execution of unauthorized software are prevented

PR.PS-06

Secure software development practices are integrated, and their performance is monitored throughout the software development life cycle