|
control enhancementCM-7(5)
Authorized Software — Allow-by-exception (CM-7(5))
Identify [organization-defined]; Employ a deny-all, permit-by-exception policy to allow the execution of authorized software programs on the system; and Review and update the list of authorized software programs [organization-defined].
Security Baselines
MODERATEHIGHLOW
configurationbaselineschange-controlenhancement
Why These Connect
Maps To3
These are equivalent or closely aligned requirements in other frameworks.
Enhances1
These enhancements add specific capabilities or refinements to the base control.
Baselined In2
This control is included in the linked security baseline (LOW, MODERATE, or HIGH).
Cross-Framework Mappings(3)
PR.PS-05PR.PS-05Final
NIST OLIR informative reference — Cybersecurity Framework v2.0 to SP 800-53 Rev 5
ISO 27001ISO/IEC 27001:20221 mappingFinal
NIST OLIR informative reference — SP 800-53 Rev 5 to ISO/IEC 27001:2022
PR.PS-05PR.PS-05Final
NIST OLIR informative reference — Cybersecurity Framework v2.0 to SP 800-53 Rev 5
Organization-Defined Parameters(2)
Assignmentorganization-defined software programs
Assignmentorganization-defined frequency