Also if your boot loader checks the signature on the kernel and the initrd then you can use the initrd to verify the rest of your system using file-based IDS.
This had the advantage over a live cd system in that it's automatable and is easier for the OS vendor to support.