What evidence supports build integrity in NIST SSDF SP 800-218?
Keep evidence that shows the build pipeline, build artifacts, and release outputs were protected from tampering and verified before distribution.
Useful records include provenance data such as an SBOM, integrity verification information such as hashes or signatures, and records showing the approved build configuration or controlled environment used for the release.
- Record the approved build configuration and controlled build environment.
- Keep integrity verification data for release files and build outputs.
- Retain provenance data for release components, such as an SBOM.
- Document who verified the build and what release gate it passed.
- Use the evidence to support release, audit, supplier, and incident reviews.
Primary NIST source for the Secure Software Development Framework.
Primary NIST source for the integrated security and privacy control catalog.
Primary NIST source for cybersecurity supply chain risk management practices.