NIST SP 800-53 Rev. 5
CM-7(4)
Configuration Management
enhancement

Unauthorized Software — Deny-by-exception

Parent: CM-7

Description

a. Identify [organization-defined parameter]; b. Employ an allow-all, deny-by-exception policy to prohibit the execution of unauthorized software programs on the system; and c. Review and update the list of unauthorized software programs [organization-defined parameter].

Mapped SPARTA techniques

22 techniques

Cite as SafeMode Space, nist-80053-rev5 CM-7(4).

Built 2026-07-25 from 216 techniques, 334 regulation articles, 125 ENISA controls, 2,610 framework controls, and 90 countermeasures.