# CM-11 User-installed Software

NIST SP 800-53 control. Family: CM Configuration Management. Function: preventative. Baselines: low, moderate, high. Mapping licence: CC BY-SA 4.0.

Statement: a. Establish [Assignment: organization-defined policies] governing the installation of software by users; b. Enforce software installation policies through the following methods: [Assignment: organization-defined methods]; and c. Monitor policy compliance [Assignment: organization-defined frequency].
Guidance: If provided the necessary privileges, users can install software in organizational systems. To maintain control over the software installed, organizations identify permitted and prohibited actions regarding software installation. Permitted software installations include updates and security patches to existing software and downloading new applications from organization-approved "app stores." Prohibited software installations include software with unknown or suspect pedigrees or software that organizations consider potentially malicious. Policies selected for governing user-installed software are organization-developed or provided by some external entity. Policy enforcement methods can include procedural methods and automated methods.

## Enhancements (2)
- CM-11(02) Software Installation with Privileged Status
- CM-11(03) Automated Enforcement and Monitoring
Withdrawn by NIST: CM-11(01) (now in CM-08(03)).
Each enhancement's statement: /api/v1/controls/CM-11?fields=enhancements

## Patterns that use it (1)
- Important (1): SP-046 External Attack Surface Management

## Clauses by framework (22 frameworks)
- iso_27001_2022: A.8.9, A.8.18, A.8.19. OSA's own, not in NIST's crosswalk: A.8.9, A.8.18
- iso_27002_2022: 5.37, 8.18, 8.19
- cobit_2019: BAI10
- nist_csf_2: DE.CM-03, DE.CM-09, PR.PS-01, PR.PS-02, PR.PS-05. OSA's own, not in NIST's crosswalk: PR.PS-05
- cis_controls_v8: CIS 2, CIS 2.3, CIS 9.4
- asd_e8: E8-1
- bio2: 5.37, 8.18, 8.19
- rbi_csf: Annex1.2
- qatar_nia: OS
- uae_ia: T7
- bom_ctrm: 3.6, 3.12
- cbe_csf: CTO-7
- sa_js2: JS2-8.4
- bot_cyber: Ch2.1, Ch2.6
- eba_ict: 3.4.4
- ecb_croe: CROE.2.3.4
- ffiec_is: II.C.11, II.C.13(e)
- sebi_cscrf: PR.ES, PR.IP
- cmmc_2: CM
- lloyds_ms: MS8.4, MS8.10
- csa_ccm_v4: UEM-02
- csa_aicm: UEM-02
OSA's mapping for iso_27001_2022 and nist_csf_2 takes NIST's published crosswalk as its base. A clause not marked as OSA's own is in that crosswalk.

## More
- This control as JSON, with guidance and ATT&CK techniques: /api/v1/controls/CM-11
- Clauses only: /api/v1/controls/CM-11?fields=mappings
- Page for people: /controls/cm-11/
