Section 94 of 102
93. Secure Updates and Signed Configurations
Stable section ID: S05-CON-010-SECTION-94 · 15 content blocks
Software, models, firmware, rules, agent Manifests, BDL schemas, and Building BIOS configurations shall be updated through controlled processes.
Updates should include:
- Source verification.
- Digital signature verification.
- Compatibility evaluation.
- Change documentation.
- Security review.
- Safety-impact review.
- Testing.
- Staged deployment.
- Rollback capability.
- Post-update verification.
An update shall not silently expand agent permissions, introduce new data collection, weaken safety limits, or modify protected configuration.
Signed configurations shall allow operational systems to verify that a package was produced and approved through a recognized process and has not been altered.
When signature verification fails, the configuration shall not be activated. The system shall retain or return to an appropriate previously verified state.