NIST SP 800-53 Rev 5 MODERATE
CM Configuration Management

NIST SP 800-53 Rev 5 MODERATE CM-7(5): Authorized Software Allow-by-Exception

Identify and maintain authorized software list; employ allowlist; review at least annually; HIGH requirement.

What else in your programme already covers this

This control maps to 33 controls across 18 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

ISO 27002:2022 · 4 controls

  • 5.9 Inventory of information and other associated assets
  • 8.19 Installation of software on operational systems
  • 8.7 Protection against malware
  • 8.9 Configuration management

PCI DSS 4.0 · 4 controls

  • 5.2.1 An anti-malware solution(s) is deployed on all system components, except for those system components identified in periodic evaluations per Requirement 5.2.3 that concludes the system components are not at risk from malware
  • 5.2.3 Any system components that are not at risk for malware are evaluated periodically to include the following: • A documented list of all system components not at risk for malware. • Identification and evaluation
  • 6.3.2 An inventory of bespoke and custom software, and third-party software components incorporated into bespoke and custom software is maintained to facilitate vulnerability and patch management
  • 8.6.3 Passwords/passphrases for any application and system accounts are protected against misuse as follows: • Passwords/passphrases are changed periodically (at the frequency defined in the entity's targeted risk analysis, which is performed according to all

ACSC Essential Eight · 3 controls

CIS Controls v8 · 3 controls

  • CIS-2.5 Allowlist Authorized Software
  • CIS-2.6 Allowlist Authorized Libraries
  • CIS-2.7 Allowlist Authorized Scripts

ISO 27001:2022 · 3 controls

  • 8.19 Installation of software on operational systems
  • 8.7 Protection against malware
  • 8.9 Configuration management
  • SEC06-BP02 Provision compute from hardened images
  • SEC11-BP05 Centralize services for packages and dependencies
  • NIST-CSF-ID.AM-02 Inventories of software, services, and systems managed by the organization are maintained
  • NIST-CSF-PR.PS-05 Installation and execution of unauthorized software are prevented

NIST SP 800-53 Rev 5 · 2 controls

  • ASD37-01 Application control (Essential)
  • AUCDR-IS-5 Limit, prevent, detect and remove malware
  • ASBv3-AM-5 Use only approved applications in virtual machine

C5 (Germany) · 1 control

  • C5-PSS-11 Images for Virtual Machines and Containers

CMMC 2.0 · 1 control

  • 03.04.08 Authorized Software - Allow by Exception

NIST SP 800-172 · 1 control

  • 3.4.1e Authoritative Source for Software and Firmware

SOC 2 · 1 control

  • SOC2-CC6.8 Controls to prevent or detect unauthorized or malicious software

UK Cyber Essentials · 1 control

  • CE-MP.4 Application Allowlisting (Alternative)

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in CM Configuration Management

Query this from an agent

The graph holds this control, the 33 it maps to, and the evidence behind each claim, over MCP and REST.