NIST Cybersecurity Framework 2.0
PR.PS-05

Installation and execution of unauthorized software are prevented

Parent: PR.PS

Description

No description available.

Mapped SPARTA techniques

4 techniques

  • Supported by two independent derivations that agree, neither of them SafeMode's invention. Through NIST 800-53: SafeMode's curated mapping records DE-0003.03 against CM-7 Least Functionality, and CSF 2.0's own crosswalk names that control as an informative reference for PR.PS-05. Through SPARTA: SPARTA's catalog maps DE-0003.03 to countermeasure CM0069 Process White Listing, and that countermeasure's own CSF references include PR.PS-05. Recorded as `addresses` rather than `mitigates` because a CSF subcategory states an outcome to be achieved while the underlying control states the mechanism that achieves it, which is the mechanism-versus-mandate ceiling in decisions entry 15.

  • DE-0003.07Cryptographic ModesST0006
    addresses
    moderate

    Supported by two independent derivations that agree, neither of them SafeMode's invention. Through NIST 800-53: SafeMode's curated mapping records DE-0003.07 against CM-7 Least Functionality, and CSF 2.0's own crosswalk names that control as an informative reference for PR.PS-05. Through SPARTA: SPARTA's catalog maps DE-0003.07 to countermeasure CM0069 Process White Listing, and that countermeasure's own CSF references include PR.PS-05. Recorded as `addresses` rather than `mitigates` because a CSF subcategory states an outcome to be achieved while the underlying control states the mechanism that achieves it, which is the mechanism-versus-mandate ceiling in decisions entry 15.

  • IA-0004.02ReceiverST0003
    addresses
    moderate

    Supported by two independent derivations that agree, neither of them SafeMode's invention. Through NIST 800-53: SafeMode's curated mapping records IA-0004.02 against CM-7 Least Functionality, and CSF 2.0's own crosswalk names that control as an informative reference for PR.PS-05. Through SPARTA: SPARTA's catalog maps IA-0004.02 to countermeasure CM0014 Secure boot; CM0021 Software Digital Signature; CM0028 Tamper Protection, and that countermeasure's own CSF references include PR.PS-05. Recorded as `addresses` rather than `mitigates` because a CSF subcategory states an outcome to be achieved while the underlying control states the mechanism that achieves it, which is the mechanism-versus-mandate ceiling in decisions entry 15.

  • PER-0002.01Hardware BackdoorST0005
    addresses
    moderate

    Supported by two independent derivations that agree, neither of them SafeMode's invention. Through NIST 800-53: SafeMode's curated mapping records PER-0002.01 against CM-7 Least Functionality, and CSF 2.0's own crosswalk names that control as an informative reference for PR.PS-05. Through SPARTA: SPARTA's catalog maps PER-0002.01 to countermeasure CM0028 Tamper Protection, and that countermeasure's own CSF references include PR.PS-05. Recorded as `addresses` rather than `mitigates` because a CSF subcategory states an outcome to be achieved while the underlying control states the mechanism that achieves it, which is the mechanism-versus-mandate ceiling in decisions entry 15.

Cross-framework references

Relationships published by the source frameworks themselves, reproduced here with attribution. They are not SafeMode Space mappings and carry no confidence rating of ours.

Cite as SafeMode Space, csf-2-0 PR.PS-05.

Built 2026-07-25 from 216 techniques, 334 regulation articles, 125 ENISA controls, 2,610 framework controls, and 90 countermeasures.