id: "CM-07(06)" title: "Confined Environments with Limited Privileges" family: "CM" family_name: "Configuration Management" sort_id: "cm-07.06" priority: "P1" implementation_level: "organization" parent: "CM-07" enhancement: True


Statement

Require that the following user-installed software execute in a confined physical or virtual machine environment with limited privileges: {{ insert: param, cm-07.06_odp }}.

Guidance

Organizations identify software that may be of concern regarding its origin or potential for containing malicious code. For this type of software, user installations occur in confined environments of operation to limit or contain damage from malicious code that may be executed.

Assessment Objective

{{ insert: param, cm-07.06_odp }} is required to be executed in a confined physical or virtual machine environment with limited privileges.

Configuration management policy

procedures addressing least functionality in the system

configuration management plan

system design documentation

system configuration settings and associated documentation

list or record of software required to execute in a confined environment

system component inventory

common secure configuration checklists

system audit records

system security plan

other relevant documents or records

Organizational personnel with responsibilities for identifying and/or managing user-installed software and associated privileges

organizational personnel with information security responsibilities

system/network administrators

Organizational process for identifying user-installed software required to execute in a confined environment

mechanisms supporting and/or implementing the confinement of user-installed software to physical or virtual machine environments

mechanisms supporting and/or implementing privilege limitations on user-installed software