| Configuration management |
8.9 |
phase0-policy.json, ENFORCEMENT_POLICY.md, signed DFIMBOOT v2 |
Change board for release counters |
| Information deletion / retention |
8.10 |
TELEMETRY.md retention guidance, redacted JSONL |
Legal retention schedule |
| Data masking |
8.11 |
Pseudonymous asset_id, no raw paths in JSONL |
Access control on audit files |
| Monitoring activities |
8.16 |
JSONL + OTel Collector, Grafana ops stack |
SOC alert routing |
| Clock synchronization |
8.17 |
UTC timestamps in audit; TPM clockInfo.safe gate |
NTP on hosts |
| Use of privileged utilities |
8.18 |
Root required for eBPF/IMA attach only |
Privileged access management |
| Software installation |
8.19 |
Attested release bundles, CROSS_PLATFORM_RELEASE.md |
Approved artifact registry |
| Network security |
8.20 |
OTLP TLS/auth is operator responsibility |
Network team |
| Security of network services |
8.21 |
N/A — DFIM is host integrity, not network service |
— |
| Segregation in networks |
8.22 |
Protected-scope limits blast radius to enrolled assets |
Architecture review |
| Web filtering |
8.23 |
N/A |
— |
| Cryptography |
8.24 |
P-256 DFIMBOOT v2, SHA-256 Merkle, TPM quotes |
HSM/KMS for production keys |
| Secure development lifecycle |
8.25 |
CI phases 0–12, fuzz/CodeQL/Kani, contracts |
Pen-test closure |
| Application security |
8.26 |
Parser bounds, fail-closed CLI, AT tests |
External pen-test |
| Secure system architecture |
8.27 |
Layered UEFI/host/eBPF model in THREAT_MODEL.md |
Deployment review |
| Secure coding |
8.28 |
Rust #![deny(unsafe_code)] in core, clippy -D warnings |
— |
| Security testing |
8.29 |
Fuzz, Kani, adversarial acceptance AT-01..09 |
Platform qualification |
| Change management |
8.32 |
Monotonic release counters, rollback baselines |
CAB approval |
| Test information |
8.33 |
Synthetic fixtures only in CI; no prod data in repo |
Test data policy |
| Protection against malware |
8.7 |
Partial — integrity enforcement, not AV |
AV remains separate control |
| Backup |
8.13 |
Recovery artifacts + RECOVERY.md |
Offline recovery media custody |
| Redundancy |
8.14 |
Stateless verify; sidecar replay from CMDB |
HA architecture |
| Logging |
8.15 |
DFIM_TELEMETRY_OUT, SIEM mapping in ENTERPRISE_INTEGRATION.md |
Log shipping SLA |