manage.get.gov/docs/compliance/dist/system-security-plans/ato/cm-11.md
Logan McDonald 1d3dfdb8d5
Add compliance documentation to source control (#116)
* add initial setup of compliance-trestle
2022-09-14 08:46:43 -04:00

2.2 KiB

implementation-status control-origination
c-not-implemented
c-inherited-cloud-gov
c-inherited-cisa
c-common-control
c-system-specific-control

cm-11 - [catalog] User-installed Software

Control Statement

  • [a] Establish policies governing the installation of software by users;

  • [b] Enforce software installation policies through the following methods: methods ; and

  • [c] Monitor policy compliance frequency.

Control guidance

If provided the necessary privileges, users can install software in organizational systems. To maintain control over the software installed, organizations identify permitted and prohibited actions regarding software installation. Permitted software installations include updates and security patches to existing software and downloading new applications from organization-approved "app stores." Prohibited software installations include software with unknown or suspect pedigrees or software that organizations consider potentially malicious. Policies selected for governing user-installed software are organization-developed or provided by some external entity. Policy enforcement methods can include procedural methods and automated methods.

Control assessment-objective

policies governing the installation of software by users are established; software installation policies are enforced through methods; compliance with policies is monitored frequency.


What is the solution and how is it implemented?


Implementation a.

Add control implementation description here for item cm-11_smt.a


Implementation b.

Add control implementation description here for item cm-11_smt.b


Implementation c.

Add control implementation description here for item cm-11_smt.c