Section 84 of 101
83. Secure Firmware and Software Updates
Stable section ID: S05-CON-006-SECTION-84 · 43 content blocks
Firmware and software updates shall preserve system integrity, compatibility, recoverability, and building safety.
Every update package shall include:
target component or service;
current and proposed versions;
publisher identity;
digital signature;
integrity value;
compatibility requirements;
affected capabilities;
configuration changes;
safety and security impact;
installation procedure;
rollback or recovery method;
required recommissioning;
release information.
Before update, the BIOS shall verify:
package authenticity;
publisher authority;
target identity;
hardware compatibility;
Interface and protocol compatibility;
available storage and power;
system operating mode;
active emergency or maintenance conditions;
dependency impact;
- recovery readiness.
- Safety-critical updates shall not proceed during incompatible operating conditions.
The update process shall follow:
acquire package;
verify integrity and signature;
evaluate compatibility and impact;
obtain required approval;
create configuration checkpoint;
isolate affected service where necessary;
install into a protected inactive environment where possible;
verify installed image;
activate;
perform health checks;
recommission affected functions;
- update configuration and evidence records.
- Interrupted or failed updates shall not leave the component in an ambiguous partially active state.
Unauthorized downgrade shall be prevented where it would reintroduce known safety or security vulnerabilities. Approved rollback shall remain possible when required for recovery.
Software support status and end-of-support dates shall be included in the Cartridge Digital Passport.