Skip to main content

💼 CM-7 (5) AUTHORIZED SOFTWARE | WHITELISTING

  • Contextual name: 💼 CM-7 (5) AUTHORIZED SOFTWARE | WHITELISTING
  • ID: /frameworks/nist-sp-800-53-r4/cm/07/05
  • Located in: 💼 CM-7 LEAST FUNCTIONALITY

Description​

The organization: CM-7 (5)(a) Identifies [Assignment: organization-defined software programs authorized to execute on the information system]; CM-7 (5)(b) Employs a deny-all, permit-by-exception policy to allow the execution of authorized software programs on the information system; and CM-7 (5)(c) Reviews and updates the list of authorized software programs [Assignment: organization-defined frequency].

Similar​

  • Internal
    • ID: dec-c-bc2ca2cf

Sub Sections​

SectionSub SectionsInternal RulesPoliciesFlags