|
controlCM-11
User-installed Software (CM-11)
Establish [organization-defined] governing the installation of software by users; Enforce software installation policies through the following methods: [organization-defined] ; and Monitor policy compliance [organization-defined].
Security Baselines
LOWMODERATEHIGH
configurationbaselineschange-control
Why These Connect
Maps To9
These are equivalent or closely aligned requirements in other frameworks.
Baselined In3
This control is included in the linked security baseline (LOW, MODERATE, or HIGH).
Supports27
These related controls work together — a change to one may affect the others.
Enhances3
These enhancements add specific capabilities or refinements to the base control.
Related Controls(16)
AC-3Access Enforcement (AC-3)
LMH
AC-5Separation of Duties (AC-5)MH
AC-6Least Privilege (AC-6)MH
AU-6Audit Record Review, Analysis, and Reporting (AU-6)LMH
CA-7Continuous Monitoring (CA-7)LMH
CM-3Configuration Change Control (CM-3)MH
CM-6Configuration Settings (CM-6)LMH
CM-7Least Functionality (CM-7)LMH
CM-8System Component Inventory (CM-8)LMH
CM-2Baseline Configuration (CM-2)LMH
CM-5Access Restrictions for Change (CM-5)LMH
PL-4Rules of Behavior (PL-4)LMH
SI-4System Monitoring (SI-4)LMH
SI-7Software, Firmware, and Information Integrity (SI-7)MH
PM-31Continuous Monitoring Strategy (PM-31)SC-13Cryptographic Protection (SC-13)LMH
Cross-Framework Mappings(9)
PR.PS-01PR.PS-01Final
NIST OLIR informative reference — Cybersecurity Framework v2.0 to SP 800-53 Rev 5
PR.PS-02PR.PS-02Final
NIST OLIR informative reference — Cybersecurity Framework v2.0 to SP 800-53 Rev 5
DE.CM-03DE.CM-03Final
NIST OLIR informative reference — Cybersecurity Framework v2.0 to SP 800-53 Rev 5
DE.CM-09DE.CM-09Final
NIST OLIR informative reference — Cybersecurity Framework v2.0 to SP 800-53 Rev 5
ISO 27001ISO/IEC 27001:20221 mappingFinal
NIST OLIR informative reference — SP 800-53 Rev 5 to ISO/IEC 27001:2022
PR.PS-01PR.PS-01Final
NIST OLIR informative reference — Cybersecurity Framework v2.0 to SP 800-53 Rev 5
PR.PS-02PR.PS-02Final
NIST OLIR informative reference — Cybersecurity Framework v2.0 to SP 800-53 Rev 5
DE.CM-03DE.CM-03Final
NIST OLIR informative reference — Cybersecurity Framework v2.0 to SP 800-53 Rev 5
DE.CM-09DE.CM-09Final
NIST OLIR informative reference — Cybersecurity Framework v2.0 to SP 800-53 Rev 5
Organization-Defined Parameters(3)
Assignmentorganization-defined policies
Assignmentorganization-defined methods
Assignmentorganization-defined frequency