PR.PS-05—Installation and execution of unauthorized software are prevented
>Control Description
This platform security subcategory ensures that installation and execution of unauthorized software are prevented. Key activities include: When risk warrants it, restrict software execution to permitted products only or deny the execution of prohibited and unauthorized software; Verify the source of new software and the software’s integrity before installing it; Configure platforms to use only approved DNS services that block access to known malicious domains.
>Cross-Framework Mappings
NIST SP 800-53 r5
via NIST CSF 2.0 Concept CrosswalkISO 27001:2022
via NIST OLIR Catalog>Informative References
Official NIST mappings to external frameworks and standards. Source: NIST CSF 2.0
CCMv4.0
CCC-04
UEM-02
UEM-09
CIS Controls v8.0
2.5
CIS Controls v8.1
2.5
CRI Profile v2.0
PR.PS-05
PR.PS-05.01
PR.PS-05.02
PR.PS-05.03
ISO/IEC 27001:2022
Mandatory Clause: None
Annex A Controls: 8.19
NICE Framework
DD-WRL-001
DD-WRL-002
IO-WRL-005
IO-WRL-007
OG-WRL-001
OG-WRL-013
PD-WRL-004
PD-WRL-007
PCI DSS
2.2.1
5.3.2
6.4.3
SCF
CFG-01
CFG-02
CFG-03
CFG-03.2
CFG-05
END-03
SP 800-53 Rev 5.1.1
CM-07(02)
CM-07(04)
CM-07(05)
SC-34
SP 800-53 Rev 5.2.0
CM-07(02)
CM-07(04)
CM-07(05)
SC-34
Ask AI
Configure your API key to use AI features.