id: "CM-07(07)" title: "Code Execution in Protected Environments" family: "CM" family_name: "Configuration Management" sort_id: "cm-07.07" priority: "P1" implementation_level: "system" parent: "CM-07" enhancement: True
Statement
Allow execution of binary or machine-executable code only in confined physical or virtual machine environments and with the explicit approval of {{ insert: param, cm-07.07_odp }} when such code is:
Obtained from sources with limited or no warranty; and/or
Without the provision of source code.
Guidance
Code execution in protected environments applies to all sources of binary or machine-executable code, including commercial software and firmware and open-source software.
Assessment Objective
the execution of binary or machine-executable code is only allowed in confined physical or virtual machine environments;
Assessment Objective: the execution of binary or machine-executable code obtained from sources with limited or no warranty is only allowed with the explicit approval of {{ insert: param, cm-07.07_odp }};
Assessment Objective: the execution of binary or machine-executable code without the provision of source code is only allowed with the explicit approval of {{ insert: param, cm-07.07_odp }}.
Configuration management policy
procedures addressing least functionality in the system
configuration management plan
system design documentation
system configuration settings and associated documentation
list or record of binary or machine-executable code
system component inventory
common secure configuration checklists
system audit records
system security plan
other relevant documents or records
Organizational personnel with responsibilities for approving execution of binary or machine-executable code
organizational personnel with information security responsibilities
organizational personnel with software management responsibilities
system/network administrators
system developers
Organizational process for approving execution of binary or machine-executable code
organizational process for confining binary or machine-executable code to physical or virtual machine environments
mechanisms supporting and/or implementing the confinement of binary or machine-executable code to physical or virtual machine environments