|
control enhancementCM-7(4)

Unauthorized Software — Deny-by-exception (CM-7(4))

Identify [organization-defined]; Employ an allow-all, deny-by-exception policy to prohibit the execution of unauthorized software programs on the system; and Review and update the list of unauthorized software programs [organization-defined].

configurationbaselineschange-controlenhancement

Why These Connect

Maps To3

These are equivalent or closely aligned requirements in other frameworks.

Enhances1

These enhancements add specific capabilities or refinements to the base control.

Cross-Framework Mappings(3)

PR.PS-05PR.PS-05Final
NIST OLIR informative reference — Cybersecurity Framework v2.0 to SP 800-53 Rev 5
ISO 27001ISO/IEC 27001:20221 mappingFinal
NIST OLIR informative reference — SP 800-53 Rev 5 to ISO/IEC 27001:2022
PR.PS-05PR.PS-05Final
NIST OLIR informative reference — Cybersecurity Framework v2.0 to SP 800-53 Rev 5

Organization-Defined Parameters(2)

Assignmentorganization-defined software programs
Assignmentorganization-defined frequency