Platform Security (PR.PS)
The hardware, software (e.g., firmware, operating systems, applications), and services of physical and virtual platforms are managed consistent with the organization's risk strategy to protect their confidentiality, integrity, and availability
Subcategories
PR.PS-01
Configuration management practices are established and applied
PR.PS-02
Software is maintained, replaced, and removed commensurate with risk
PR.PS-03
Hardware is maintained, replaced, and removed commensurate with risk
PR.PS-04
Log records are generated and made available for continuous monitoring
PR.PS-05
Installation and execution of unauthorized software are prevented
PR.PS-06
Secure software development practices are integrated, and their performance is monitored throughout the software development life cycle