Under active development Content is continuously updated and improved

CM-7(5)Least Functionality | Authorized Software

>Control Description

(a) Identify organization-defined software programs authorized to execute on the system; (b) Employ a deny-all, permit-by-exception policy to allow the execution of authorized software programs on the system; and (c) Review and update the list of authorized software programs organization-defined frequency.

>Related Controls

Ask AI

Configure your API key to use AI features.