CM-11 User-installed software
Requires policies governing user installation of software to be established, enforced through organization-defined methods, and monitored for compliance on an organization-defined frequency.
4
artefacts
2
held by a system
1
at each review
easy
to go live
Cloud console / configuration management
where the evidence lives
teal = a system already holds it · olive = produced at each review
system holds itEvidence a system already holds
- Technical enforcement configuration such as application allow listing or removal of local administrator rights · Cloud console / configuration management
- Compliance monitoring output at the defined frequency · SIEM / log platform
periodic reviewEvidence produced at each review
- Exception records for users permitted to install, with justification · Cloud console / configuration management
governing documentDocuments that govern the control
- User software installation policy stating what users may and may not install · Policy repository / GRC workspace
First move
Automate the pull from your Cloud console / configuration management. Configuration snapshots and change history from the cloud console or IaC repository, diffed against the baseline.
Common gaps auditors find
- Policy written but users retain local administrator rights, so nothing enforces it
- Enforcement applied to workstations while servers and cloud instances are unmanaged
- No monitoring, so unauthorized software is only found during incidents
Do this for your whole sheet
Paste the rows you run your controls from and get this mapping for every control at once, with the periodic-review ones flagged and a first move per row. No account for the first run.
Build my evidence sheetCM-10 Software usage restrictions · CM-12 Information Location. Identify and document the location of [organization-defined] and the specific system components on which the information is processed and stored; Identify and document the users who have access to the system and