Cyber Posture

NIST 800-53 r5 · Controls catalogue · Family CM

CM-14Signed Components

Prevent the installation of {{ insert: param, cm-14_prm_1 }} without verification that the component has been digitally signed using a certificate that is recognized and approved by the organization.

Last updated: 09 May 2026 03:25 UTC

Implementations targeting this control (0)

ATT&CK techniques this control mitigates (0)

Weaknesses this control addresses (3)AI

CWEs ranked by how often they appear in real CVEs. The rationale describes how this control reduces exploitability of each weakness class.

CWE Name CVEs Why this control addresses it
CWE-347Improper Verification of Cryptographic Signature778Requires verification of digital signatures using organization-approved certificates before installation, directly preventing improper verification of cryptographic signatures.
CWE-494Download of Code Without Integrity Check242Blocks installation of components lacking a valid signature, mitigating download or installation of code without integrity checks.
CWE-353Missing Support for Integrity Check37Implements required signature-based integrity verification, addressing missing support for integrity checks on components.

Top CVEs where this control is the strongest mitigation

CVE Risk CVSS EPSS Match
CVE-2025-662552.09.80.0038good
CVE-2025-276702.09.80.0016good
CVE-2025-432452.09.80.0013good
CVE-2025-276801.89.10.0023good
CVE-2024-413341.88.80.0014good
CVE-2026-400661.88.80.0003good
CVE-2025-686231.88.80.0001good
CVE-2024-73441.78.20.0039good
CVE-2026-329201.78.40.0002good
CVE-2024-111281.67.80.0006good
CVE-2025-05091.57.30.0007good
CVE-2026-37801.57.30.0001good
CVE-2024-561611.47.20.0008good
CVE-2025-122951.36.60.0024good
CVE-2025-241091.15.50.0010good
CVE-2025-30154 KEV5.88.60.3399good
CVE-2026-271804.99.80.4880good
CVE-2025-15556 KEV3.97.50.0609good
CVE-2026-3502 KEV3.77.80.0275good
CVE-2023-539592.09.80.0037good
CVE-2026-344242.09.80.0024good
CVE-2024-563362.09.80.0031good
CVE-2025-261552.09.80.0008good
CVE-2025-342122.09.80.0067good
CVE-2025-498412.09.80.0034good

Other controls in family CM

CM-1 CM-10 CM-11 CM-12 CM-13 CM-2 CM-3 CM-4 CM-5 CM-6 CM-7 CM-8 CM-9