NIST SP 800-53 Rev. 5
CM-7(5)
Configuration Management
enhancement

Authorized Software — Allow-by-exception

Parent: CM-7

Description

a. Identify [organization-defined parameter]; b. Employ a deny-all, permit-by-exception policy to allow the execution of authorized software programs on the system; and c. Review and update the list of authorized software programs [organization-defined parameter].

Mapped SPARTA techniques

123 techniques

Cite as SafeMode Space, nist-80053-rev5 CM-7(5).

Built 2026-07-25 from 216 techniques, 334 regulation articles, 125 ENISA controls, 2,610 framework controls, and 90 countermeasures.