NIST 800-53 Rev 5

424 controls available

CM-11lowmoderatehigh

User-installed Software

Configuration Management

Control Statement

Establish {{ insert: param, cm-11_odp.01 }} governing the installation of software by users; Enforce software installation policies through the following methods: {{ insert: param, cm-11_odp.02 }} ; and Monitor policy compliance {{ insert: param, cm-11_odp.03 }}.

Discussion

If provided the necessary privileges, users can install software in organizational systems. To maintain control over the software installed, organizations identify permitted and prohibited actions regarding software installation. Permitted software installations include updates and security patches to existing software and downloading new applications from organization-approved "app stores." Prohibited software installations include software with unknown or suspect pedigrees or software that organizations consider potentially malicious. Policies selected for governing user-installed software are organization-developed or provided by some external entity. Policy enforcement methods can include procedural methods and automated methods.

Framework
NIST SP 800-53 Rev 5
Family
Configuration Management
Baselines
low, moderate, high

Related Frameworks

13 paths across 3 frameworks
SCF2 mappings
CFG-05User-Installed Software
0.50
  • Secure Controls Framework · 2026.2 · scf_strm · related
END-03Prohibit Installation Without Privileged Status
0.50
  • Secure Controls Framework · 2026.2 · scf_strm · related
NIST 800-1711 mapping
3.4.9
1.00
  • NIST · Rev 2 (Feb 2020, errata Jan 2021) · nist_800_171_app_d · equivalent
CCI8 mappings
CCI-001804
1.00
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-001805
1.00
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-001806
1.00
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-001807
1.00
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-001808
1.00
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-001809
1.00
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-001812
0.25
  • Secure Controls Framework · 2026.2 · scf_strm · related
  • Secure Controls Framework · 2026.2 · scf_strm · related
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-003980
0.25
  • Secure Controls Framework · 2026.2 · scf_strm · related
  • Secure Controls Framework · 2026.2 · scf_strm · related
  • DISA · 2025-01-23 · disa_cci_list · equivalent

Related STIGs

78 STIGs reach this control through 11 CCIs. Expand a row to see the responsible NICE and O*NET roles.

Operating System - Desktop

7 STIGs

Operating System - Server

10 STIGs
Anduril NixOS Security Technical Implementation Guide
V1R22025-08-191 of 103 findings match
Show 2 more STIGs in this category →

Operating System - Mainframe

3 STIGs
Mainframe Product Security Requirements Guide
32024-12-051 of 193 findings match
Mainframe Product Security Requirements Guide
V3R42025-09-101 of 194 findings match

Network Device

9 STIGs

Database

16 STIGs
Database Security Requirements Guide
42024-12-041 of 142 findings match
Database Security Requirements Guide
V4R52026-02-261 of 142 findings match
Show 8 more STIGs in this category →

Web / Application Server

6 STIGs

Virtualization / Container

6 STIGs
Container Platform Security Requirements Guide
22025-05-153 of 187 findings match
Container Platform Security Requirements Guide
V2R42025-09-103 of 188 findings match
Virtual Machine Manager Security Requirements Guide
22024-12-061 of 193 findings match
Virtual Machine Manager Security Requirements Guide
V2R32025-09-101 of 198 findings match

Endpoint Security Management

5 STIGs

Productivity Application

2 STIGs
Microsoft Edge Security Technical Implementation Guide
V2R52026-02-251 of 61 findings match

Uncategorized

14 STIGs
Show 6 more STIGs in this category →
Mainframe Product Security Requirements Guide
V3R52026-05-231 of 194 findings match
Network Device Management Security Requirements Guide
V5R52026-05-231 of 99 findings match
Virtual Machine Manager Security Requirements Guide
V2R42026-06-291 of 198 findings match