id: "CM-07(04)" title: "Unauthorized Software — Deny-by-exception" family: "CM" family_name: "Configuration Management" sort_id: "cm-07.04" priority: "P1" implementation_level: "system" parent: "CM-07" enhancement: True


Identify {{ insert: param, cm-07.04_odp.01 }};

Employ an allow-all, deny-by-exception policy to prohibit the execution of unauthorized software programs on the system; and

Review and update the list of unauthorized software programs {{ insert: param, cm-07.04_odp.02 }}.

Guidance

Unauthorized software programs can be limited to specific versions or from a specific source. The concept of prohibiting the execution of unauthorized software may also be applied to user actions, system ports and protocols, IP addresses/ranges, websites, and MAC addresses.

Assessment Objective: {{ insert: param, cm-07.04_odp.01 }} are identified;

Assessment Objective: an allow-all, deny-by-exception policy is employed to prohibit the execution of unauthorized software programs on the system;

Assessment Objective: the list of unauthorized software programs is reviewed and updated {{ insert: param, cm-07.04_odp.02 }}.

Configuration management policy

procedures addressing least functionality in the system

configuration management plan

system design documentation

system configuration settings and associated documentation

list of software programs not authorized to execute on the system

system component inventory

common secure configuration checklists

review and update records associated with list of unauthorized software programs

change control records

system audit records

system security plan

other relevant documents or records

Organizational personnel with responsibilities for identifying software not authorized to execute on the system

organizational personnel with information security responsibilities

system/network administrators

Organizational process for identifying, reviewing, and updating programs not authorized to execute on the system

organizational process for implementing unauthorized software policy

mechanisms supporting and/or implementing unauthorized software policy