The content of the CSF file ( keys, key number, description of area covered etc... gets converted into a binary structure (i.e. the certificate is included in DER form. )
This complete structure is signed.
The content of the structure describes what else is covered by the signature. I am not sure how the details of the signing work.
Depending of the HAB version there is a fast verify that only uses the one of the SRK's or the old way which uses 2 certificates (the SRK one and a separate siginign certificate). But the CSF including the certs and the refrenced memory, is verified.
Simple answer: Yes the integrity of both is secured.