Describes steady-state trust concepts, encompassing SELinux implementation and policy, secure installation mechanisms such as RPM signature validation, SSD encryption with DM-Crypt and data zeroization, runtime defenses, boot integrity and trust visibility, secure gRPC session practices, and the Integrity Measurement Architecture.
Steady-state trust is a runtime trustworthy systems state that
-
maintains protection after boot
-
uses operating system and storage controls, and
-
provides visibility into software integrity.
The third component in implementing a trustworthy system is to maintain trust in the steady or runtime state.
Attackers are seeking long-term compromise of systems and using effective techniques to compromise and persist within critical infrastructure devices. Hence, it is critical to establish and maintain trust within the network infrastructure devices at all points during the system runtime.
Additional reference information
In Cisco IOS XR7, trust is established and maintained in a steady state through:
-
SELinux
-
SELinux Policy
-
SELinux Mode
-
-
Secure Install
-
RPM Signing and Validation
-
Third-Party RPMs
-
-
SSD Encryption
