EvidenceSheet

CM-11 User-installed software

Requires policies governing user installation of software to be established, enforced through organization-defined methods, and monitored for compliance on an organization-defined frequency.

4
artefacts
2
held by a system
1
at each review
easy
to go live
Cloud console / configuration management
where the evidence lives
teal = a system already holds it · olive = produced at each review

system holds itEvidence a system already holds

  • Technical enforcement configuration such as application allow listing or removal of local administrator rights · Cloud console / configuration management
  • Compliance monitoring output at the defined frequency · SIEM / log platform

periodic reviewEvidence produced at each review

  • Exception records for users permitted to install, with justification · Cloud console / configuration management

governing documentDocuments that govern the control

  • User software installation policy stating what users may and may not install · Policy repository / GRC workspace

First move

Automate the pull from your Cloud console / configuration management. Configuration snapshots and change history from the cloud console or IaC repository, diffed against the baseline.

Common gaps auditors find

Do this for your whole sheet

Paste the rows you run your controls from and get this mapping for every control at once, with the periodic-review ones flagged and a first move per row. No account for the first run.

Build my evidence sheet

CM-10 Software usage restrictions · CM-12 Information Location. Identify and document the location of [organization-defined] and the specific system components on which the information is processed and stored; Identify and document the users who have access to the system and