id: "CM-07(06)" title: "Confined Environments with Limited Privileges" family: "CM" family_name: "Configuration Management" sort_id: "cm-07.06" priority: "P1" implementation_level: "organization" parent: "CM-07" enhancement: True
Statement
Require that the following user-installed software execute in a confined physical or virtual machine environment with limited privileges: {{ insert: param, cm-07.06_odp }}.
Guidance
Organizations identify software that may be of concern regarding its origin or potential for containing malicious code. For this type of software, user installations occur in confined environments of operation to limit or contain damage from malicious code that may be executed.
Assessment Objective
{{ insert: param, cm-07.06_odp }} is required to be executed in a confined physical or virtual machine environment with limited privileges.
Configuration management policy
procedures addressing least functionality in the system
configuration management plan
system design documentation
system configuration settings and associated documentation
list or record of software required to execute in a confined environment
system component inventory
common secure configuration checklists
system audit records
system security plan
other relevant documents or records
Organizational personnel with responsibilities for identifying and/or managing user-installed software and associated privileges
organizational personnel with information security responsibilities
system/network administrators
Organizational process for identifying user-installed software required to execute in a confined environment
mechanisms supporting and/or implementing the confinement of user-installed software to physical or virtual machine environments
mechanisms supporting and/or implementing privilege limitations on user-installed software