Skip to main content

πŸ’Ό CM-11 User-installed Software

  • Contextual name: πŸ’Ό CM-11 User-installed Software
  • ID: /frameworks/nist-sp-800-53-r5/cm/11
  • Located in: πŸ’Ό CM Configuration Management

Description​

a. Establish [Assignment: organization-defined policies] governing the installation of software by users; b. Enforce software installation policies through the following methods: [Assignment: organization-defined methods]; and c. Monitor policy compliance [Assignment: organization-defined frequency].

Similar​

  • Internal
    • ID: dec-c-56e23263

Similar Sections (Give Policies To)​

SectionSub SectionsInternal RulesPoliciesFlags
πŸ’Ό FedRAMP High Security Controls β†’ πŸ’Ό CM-11 User-installed Software (L)(M)(H)44
πŸ’Ό FedRAMP Low Security Controls β†’ πŸ’Ό CM-11 User-installed Software (L)(M)(H)4
πŸ’Ό NIST CSF v2.0 β†’ πŸ’Ό DE.CM-03: Personnel activity and technology usage are monitored to find potentially adverse events59
πŸ’Ό NIST CSF v2.0 β†’ πŸ’Ό DE.CM-09: Computing hardware and software, runtime environments, and their data are monitored to find potentially adverse events89

Sub Sections​

SectionSub SectionsInternal RulesPoliciesFlags
πŸ’Ό CM-11(1) User-installed Software _ Alerts for Unauthorized Installations
πŸ’Ό CM-11(2) User-installed Software _ Software Installation with Privileged Status
πŸ’Ό CM-11(3) User-installed Software _ Automated Enforcement and Monitoring