NIST Cybersecurity Framework 2.0
PR - Protect

NIST Cybersecurity Framework 2.0 NIST-CSF-PR.PS-05: Installation and execution of unauthorized software are prevented

Installation and execution of unauthorized software are prevented

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 119 controls across 30 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

NIST SP 800-53 Rev 5 · 9 controls

PCI DSS 4.0 · 9 controls

  • 12.2.1 12.2.1 Rules for acceptable use of end-user technology
  • 2.2.4 2.2.4 Only necessary functionality enabled
  • 5.3.5 5.3.5 Users cannot disable or alter anti-malware
  • 9.4.4 9.4.4 Management approval for media leaving facility
  • 5.2.1 5.2.1 Anti-malware deployed on all system components
  • 5.3.2 5.3.2 Periodic and real-time scans or continuous behavioural analysis
  • 6.4.3 6.4.3 Payment page script management
  • 6.5.1 6.5.1 Change control procedure for production
  • 8.6.2 8.6.2 No hard-coded passwords for interactive system accounts

CIS Controls v8 · 8 controls

  • CIS-10.1 Deploy and Maintain Anti-Malware Software
  • CIS-13.7 Deploy a Host-Based Intrusion Prevention Solution
  • CIS-2.3 Address Unauthorized Software
  • CIS-2.5 Allowlist Authorized Software
  • CIS-2.6 Allowlist Authorized Libraries
  • CIS-2.7 Allowlist Authorized Scripts
  • CIS-9.1 Ensure Use of Only Fully Supported Browsers and Email Clients
  • CIS-9.4 Restrict Unnecessary or Unauthorized Browser and Email Client Extensions

FedRAMP High · 8 controls

  • CM-10 Software Usage Restrictions
  • CM-11 User-Installed Software
  • CM-7 Least Functionality
  • CM-7(2) Prevent Program Execution
  • CM-7(5) Authorized Software Allow-by-Exception
  • MA-3 Maintenance Tools (MA-3)
  • MA-3(1) Maintenance Tools | Inspect Tools (MA-3(1))
  • SC-18 Mobile Code

FedRAMP Moderate · 8 controls

  • CM-10 Software Usage Restrictions
  • CM-11 User-Installed Software
  • CM-7 Least Functionality
  • CM-7(2) Prevent Program Execution
  • CM-7(5) Authorized Software Allow-by-Exception
  • MA-3 Maintenance Tools (MA-3)
  • MA-3(1) Maintenance Tools | Inspect Tools (MA-3(1))
  • SC-18 Mobile Code

CMMC 2.0 · 6 controls

ISO 27002:2022 · 6 controls

  • 5.10 Acceptable use of information and other associated assets
  • 8.18 Use of privileged utility programs
  • 8.19 Installation of software on operational systems
  • 8.2 Privileged access rights
  • 8.3 Information access restriction
  • 8.7 Protection against malware
  • ASD37-01 Application control (Essential)
  • ASD37-03 Configure Microsoft Office macro settings (Essential)
  • ASD37-12 Antivirus software with heuristics (Very Good)
  • ASD37-13 Control removable storage media (Very Good)
  • ASD37-18 Restrict administrative privileges (Essential)

ISO 27001:2022 · 5 controls

  • 8.18 Use of privileged utility programs
  • 8.19 Installation of software on operational systems
  • 8.2 Privileged access rights
  • 8.3 Information access restriction
  • 8.7 Protection against malware

NIST SP 800-171 Rev 3 · 5 controls

  • SEC06-BP02 Provision compute from hardened images
  • SEC06-BP03 Reduce manual management and interactive access
  • SEC06-BP04 Validate software integrity
  • SEC11-BP05 Centralize services for packages and dependencies

C5 (Germany) · 4 controls

  • C5-AM-02 Acceptable Use and Safe Handling of Assets Policy
  • C5-OPS-04 Protection Against Malware - Concept
  • C5-OPS-05 Protection Against Malware - Implementation
  • C5-PSS-11 Images for Virtual Machines and Containers

HIPAA Security Rule · 4 controls

NIST SP 800-161 Rev 1 · 4 controls

NIST SP 800-66 Rev 2 · 4 controls

  • ANSSI-HYG-14 Apply a Minimum Security Level Across the Whole Estate
  • ANSSI-HYG-15 Protect Against Threats Related to Removable Media
  • ANSSI-HYG-29 Limit Administration Rights on Workstations to Operational Need
  • ISM-0843 Application control on workstations
  • ISM-1592 Blocking user installation of unapproved applications
  • ISM-1657 Application control scope of file types
  • AM-2 Use only approved services
  • ASBv3-AM-5 Use only approved applications in virtual machine
  • ES-2 Use modern anti-malware software

ISO 27701:2019 · 3 controls

  • 6.6.4 System and application access control
  • 6.9.2 Protection from malware
  • 6.9.5 Control of operational software

NIST SP 800-172 · 3 controls

  • 3.14.1e Verify Integrity of Security Critical Software and Firmware
  • 3.4.1e Authoritative Source for Software and Firmware
  • 3.4.2e Automated Detection and Remediation of Unauthorized Software

ACSC Essential Eight · 2 controls

  • E8-APP-ML1 Application Control (ML1)
  • E8-MACRO-ML3 Configure Microsoft Office Macro Settings (ML3)

SOC 2 · 2 controls

  • SOC2-CC6.1 CC6.1 Logical access security over protected information assets
  • SOC2-CC6.8 CC6.8 Preventing and detecting unauthorised or malicious software

UK Cyber Essentials · 2 controls

  • CE-MP.4 Application Allowlisting (Alternative)
  • CE-SC.1 Remove or Disable Unused Software
  • AUCDR-IS-5 Limit, prevent, detect and remove malware

NIS2 Directive · 1 control

  • Art.21.2.g Basic cyber hygiene practices and cybersecurity training

NIST SP 800-218 · 1 control

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in PR - Protect

You are reading one control. How much of NIST Cybersecurity Framework 2.0 have you already done?

NIST Cybersecurity Framework 2.0 NIST-CSF-PR.PS-05 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of NIST Cybersecurity Framework 2.0 your existing evidence covers. Hold ISO 27001:2022 and 73 of 106 NIST Cybersecurity Framework 2.0 controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 174 were rejected on the ISO 27001:2022 pair alone.

Query this from an agent

The graph holds this control, the 119 it maps to, and the evidence behind each claim, over MCP and REST.