>myctrl.tools
GitHub

CM-7(4)Unauthorized Software — Deny-By-Exception

>Control Description

a. Identify [Assignment: organization-defined software programs not authorized to execute on the system]; b. Employ an allow-all, deny-by-exception policy to prohibit the execution of unauthorized software programs on the system; and c. Review and update the list of unauthorized software programs [Assignment: organization-defined frequency].

>Supplemental Guidance

Unauthorized software programs can be limited to specific versions or from a specific source. The concept of prohibiting the execution of unauthorized software may also be applied to user actions, system ports and protocols, IP addresses/ranges, websites, and MAC addresses.

>Related Controls