Skip to main content

💼 CM-11 User-installed Software

  • Contextual name: 💼 CM-11 User-installed Software
  • ID: /frameworks/nist-sp-800-53-r5/cm/11
  • Located in: 💼 CM Configuration Management

Description​

a. Establish [Assignment: organization-defined policies] governing the installation of software by users; b. Enforce software installation policies through the following methods: [Assignment: organization-defined methods]; and c. Monitor policy compliance [Assignment: organization-defined frequency].

Similar​

  • Internal
    • ID: dec-c-56e23263

Similar Sections (Give Policies To)​

SectionSub SectionsInternal RulesPoliciesFlags
💼 FedRAMP High Security Controls → 💼 CM-11 User-installed Software (L)(M)(H)44
💼 FedRAMP Low Security Controls → 💼 CM-11 User-installed Software (L)(M)(H)4
💼 NIST CSF v2.0 → 💼 DE.CM-03: Personnel activity and technology usage are monitored to find potentially adverse events81
💼 NIST CSF v2.0 → 💼 DE.CM-09: Computing hardware and software, runtime environments, and their data are monitored to find potentially adverse events137

Sub Sections​

SectionSub SectionsInternal RulesPoliciesFlags
💼 CM-11(1) User-installed Software _ Alerts for Unauthorized Installations
💼 CM-11(2) User-installed Software _ Software Installation with Privileged Status
💼 CM-11(3) User-installed Software _ Automated Enforcement and Monitoring