Section 77 of 101
76. Root of Trust
Stable section ID: S05-CON-006-SECTION-77 · 32 content blocks
The Root of Trust is the protected foundation from which BIOS identity, software integrity, configuration authenticity, and credential validity are established.
The Root of Trust shall provide, as applicable:
unique BIOS hardware identity;
protected cryptographic operations;
secure storage of root credentials;
verification of BIOS startup software;
verification of signed configuration;
verification of trusted updates;
protection against unauthorized rollback;
recording of platform-integrity measurements;
recovery authorization.
The Root of Trust may be implemented through dedicated security hardware, protected processor capabilities, physically secured modules, or an approved combination.
The Root of Trust shall be separable from a specific software vendor account. Loss of a vendor service shall not make the building permanently inaccessible to its authorized owner or successor operator.
The trust hierarchy shall identify:
System05 governance authorities;
certification authorities;
building ownership authority;
project commissioning authority;
manufacturer authorities;
BIOS platform authority;
- recovery authority.
- No single manufacturer credential shall automatically authorize control over the complete building.
Root credentials shall have defined:
issuer;
purpose;
validity;
storage method;
permitted use;
rotation procedure;
revocation procedure;
recovery method.
Compromise or suspected compromise of the Root of Trust shall trigger restricted operation and a controlled recovery process. Re-establishing trust shall preserve the building’s identity and historical records while replacing compromised credentials.