In this video, we examine steps an organization can take to ensure that firmware and other elements of new devices have not been maliciously altered somewhere in the supply chain. Supply chain security, which I cover in the video above, is essential to an overall security program, including validating that what we expect to be installed on our devices is unaltered and safe.
The content of this video is primarily based on NIST SP 1800-34A. I included the link in the video description.
The script for this video is also available in a link in the video description.
==========
Video Script
https://adventuresinsecurity.com/_You...
==========
Works Cited/Selected Bibliography
Boyens, Jon, et al. “Validating the Integrity of Computing Devices, SP 1800-34.” NIST, 9 Dec. 2022, doi.org/10.6028/NIST.SP.1800-34. Accessed 31 July 2023.
Olzak, Tom. “UEFI and the TPM: Building a Foundation for Platform Trust | Infosec.” Resources.infosecinstitute.com, 18 Sept. 2011, resources.infosecinstitute.com/topics/management-compliance-auditing/uefi-and-tpm/. Accessed 31 July 2023.
Sinha, Sushovon. “UEFI Secure Boot in Windows 8.1.” Microsoft, 12 Nov. 2013, answers.microsoft.com/en-us/windows/forum/all/uefi-secure-boot-in-windows-81/65d74e19-9572-4a91-85aa-57fa783f0759. Accessed 31 July 2023.
Zimmer, V. J., et al. “Trusted Platforms: UEFI, PI and TCG-Based Firmware.” Intel, Sept. 2009.
==========