|
controlCM-11

User-installed Software (CM-11)

Establish [organization-defined] governing the installation of software by users; Enforce software installation policies through the following methods: [organization-defined] ; and Monitor policy compliance [organization-defined].

Security Baselines

LOWMODERATEHIGH
configurationbaselineschange-control

Why These Connect

Maps To9

These are equivalent or closely aligned requirements in other frameworks.

Baselined In3

This control is included in the linked security baseline (LOW, MODERATE, or HIGH).

Supports27

These related controls work together — a change to one may affect the others.

Enhances3

These enhancements add specific capabilities or refinements to the base control.

Cross-Framework Mappings(9)

PR.PS-01PR.PS-01Final
NIST OLIR informative reference — Cybersecurity Framework v2.0 to SP 800-53 Rev 5
PR.PS-02PR.PS-02Final
NIST OLIR informative reference — Cybersecurity Framework v2.0 to SP 800-53 Rev 5
DE.CM-03DE.CM-03Final
NIST OLIR informative reference — Cybersecurity Framework v2.0 to SP 800-53 Rev 5
DE.CM-09DE.CM-09Final
NIST OLIR informative reference — Cybersecurity Framework v2.0 to SP 800-53 Rev 5
ISO 27001ISO/IEC 27001:20221 mappingFinal
NIST OLIR informative reference — SP 800-53 Rev 5 to ISO/IEC 27001:2022
PR.PS-01PR.PS-01Final
NIST OLIR informative reference — Cybersecurity Framework v2.0 to SP 800-53 Rev 5
PR.PS-02PR.PS-02Final
NIST OLIR informative reference — Cybersecurity Framework v2.0 to SP 800-53 Rev 5
DE.CM-03DE.CM-03Final
NIST OLIR informative reference — Cybersecurity Framework v2.0 to SP 800-53 Rev 5
DE.CM-09DE.CM-09Final
NIST OLIR informative reference — Cybersecurity Framework v2.0 to SP 800-53 Rev 5

Organization-Defined Parameters(3)

Assignmentorganization-defined policies
Assignmentorganization-defined methods
Assignmentorganization-defined frequency

Control Enhancements(3)