id: "CM-11" title: "User-installed Software" family: "CM" family_name: "Configuration Management" sort_id: "cm-11" priority: "P1" implementation_level: "organization" enhancements: - cm-11.1 - cm-11.2 - cm-11.3
Establish {{ insert: param, cm-11_odp.01 }} governing the installation of software by users;
Enforce software installation policies through the following methods: {{ insert: param, cm-11_odp.02 }} ; and
Monitor policy compliance {{ insert: param, cm-11_odp.03 }}.
Guidance
If provided the necessary privileges, users can install software in organizational systems. To maintain control over the software installed, organizations identify permitted and prohibited actions regarding software installation. Permitted software installations include updates and security patches to existing software and downloading new applications from organization-approved "app stores." Prohibited software installations include software with unknown or suspect pedigrees or software that organizations consider potentially malicious. Policies selected for governing user-installed software are organization-developed or provided by some external entity. Policy enforcement methods can include procedural methods and automated methods.
Assessment Objective: {{ insert: param, cm-11_odp.01 }} governing the installation of software by users are established;
Assessment Objective: software installation policies are enforced through {{ insert: param, cm-11_odp.02 }};
Assessment Objective: compliance with {{ insert: param, cm-11_odp.01 }} is monitored {{ insert: param, cm-11_odp.03 }}.
Configuration management policy
procedures addressing user-installed software
configuration management plan
system security plan
system design documentation
system configuration settings and associated documentation
list of rules governing user installed software
system monitoring records
system audit records
continuous monitoring strategy
system security plan
other relevant documents or records
Organizational personnel with responsibilities for governing user-installed software
organizational personnel operating, using, and/or maintaining the system
organizational personnel monitoring compliance with user-installed software policy
organizational personnel with information security responsibilities
system/network administrators
Organizational processes governing user-installed software on the system
mechanisms enforcing policies and methods for governing the installation of software by users
mechanisms monitoring policy compliance