id: "CM-07(08)" title: "Binary or Machine Executable Code" family: "CM" family_name: "Configuration Management" sort_id: "cm-07.08" priority: "P1" implementation_level: "system" parent: "CM-07" enhancement: True


Prohibit the use of binary or machine-executable code from sources with limited or no warranty or without the provision of source code; and

Allow exceptions only for compelling mission or operational requirements and with the approval of the authorizing official.

Guidance

Binary or machine executable code applies to all sources of binary or machine-executable code, including commercial software and firmware and open-source software. Organizations assess software products without accompanying source code or from sources with limited or no warranty for potential security impacts. The assessments address the fact that software products without the provision of source code may be difficult to review, repair, or extend. In addition, there may be no owners to make such repairs on behalf of organizations. If open-source software is used, the assessments address the fact that there is no warranty, the open-source software could contain back doors or malware, and there may be no support available.

Assessment Objective: the use of binary or machine-executable code is prohibited when it originates from sources with limited or no warranty or without the provision of source code;

Assessment Objective: exceptions to the prohibition of binary or machine-executable code from sources with limited or no warranty or without the provision of source code are allowed only for compelling mission or operational requirements;

Assessment Objective: exceptions to the prohibition of binary or machine-executable code from sources with limited or no warranty or without the provision of source code are allowed only with the approval of the authorizing official.

Configuration management policy

procedures addressing least functionality in the system

configuration management plan

system security plan

system design documentation

system configuration settings and associated documentation

list or record of binary or machine-executable code

system component inventory

common secure configuration checklists

system audit records

system security plan

other relevant documents or records

Organizational personnel with responsibilities for determining mission and operational requirements

authorizing official for the system

organizational personnel with information security responsibilities

organizational personnel with software management responsibilities

system/network administrators

Organizational process for approving execution of binary or machine-executable code

mechanisms supporting and/or implementing the prohibition of binary or machine-executable code