id: "CM-07(07)" title: "Code Execution in Protected Environments" family: "CM" family_name: "Configuration Management" sort_id: "cm-07.07" priority: "P1" implementation_level: "system" parent: "CM-07" enhancement: True


Statement

Allow execution of binary or machine-executable code only in confined physical or virtual machine environments and with the explicit approval of {{ insert: param, cm-07.07_odp }} when such code is:

Obtained from sources with limited or no warranty; and/or

Without the provision of source code.

Guidance

Code execution in protected environments applies to all sources of binary or machine-executable code, including commercial software and firmware and open-source software.

Assessment Objective

the execution of binary or machine-executable code is only allowed in confined physical or virtual machine environments;

Assessment Objective: the execution of binary or machine-executable code obtained from sources with limited or no warranty is only allowed with the explicit approval of {{ insert: param, cm-07.07_odp }};

Assessment Objective: the execution of binary or machine-executable code without the provision of source code is only allowed with the explicit approval of {{ insert: param, cm-07.07_odp }}.

Configuration management policy

procedures addressing least functionality in the system

configuration management plan

system design documentation

system configuration settings and associated documentation

list or record of binary or machine-executable code

system component inventory

common secure configuration checklists

system audit records

system security plan

other relevant documents or records

Organizational personnel with responsibilities for approving execution of binary or machine-executable code

organizational personnel with information security responsibilities

organizational personnel with software management responsibilities

system/network administrators

system developers

Organizational process for approving execution of binary or machine-executable code

organizational process for confining binary or machine-executable code to physical or virtual machine environments

mechanisms supporting and/or implementing the confinement of binary or machine-executable code to physical or virtual machine environments