unified
UC-CONFIG-05 — Permit only authorized software installation and use
Restrict installation of software on operational systems to authorized personnel installing approved software from trusted sources, and govern user-installed software through explicit policy and technical enforcement such as allowlisting. Combine these restrictions with anti-malware controls that prevent or detect and act upon unauthorized or malicious software. Track software installation and use to comply with contract terms and license entitlements.
Record JSON · Open in map · Data retrieval guide
Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.
Attributes
- domain
- Secure Configuration & Change Management
- type
- preventive
- category
- technical
Details
- unified_id
- UC-CONFIG-05
- title
- Permit only authorized software installation and use
- statement
- Restrict installation of software on operational systems to authorized personnel installing approved software from trusted sources, and govern user-installed software through explicit policy and technical enforcement such as allowlisting. Combine these restrictions with anti-malware controls that prevent or detect and act upon unauthorized or malicious software. Track software installation and use to comply with contract terms and license entitlements.
- domain
- Secure Configuration & Change Management
- control_type
- preventive
- control_category
- technical
- members
- framework
- nist-800-53
- control_id
- CM-10
- coverage
- full
- relationship
- superset_of
- framework
- nist-800-53
- control_id
- CM-11
- coverage
- full
- relationship
- superset_of
- framework
- iso-27001
- control_id
- A.8.19
- coverage
- full
- relationship
- superset_of
- framework
- soc2
- control_id
- CC6.8
- coverage
- full
- relationship
- superset_of
- guidance
Source
No record-specific source URL is provided.
Connections
- SOC 2 Trust Services Readiness tests UC-CONFIG-05 — Permit only authorized software installation and use
- Authorized Software & Component Integrity Control operates UC-CONFIG-05 — Permit only authorized software installation and use
- UC-CONFIG-05 — Permit only authorized software installation and use maps_to CC6.8 — The entity implements controls to prevent or detect and act upon the introduction of unauthorized or malicious software to meet the entity's objectives.
- framework
- soc2
- control_id
- CC6.8
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- 2017 TSC
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- UC-CONFIG-05 — Permit only authorized software installation and use maps_to A.8.19 — Installation of software on operational systems
- framework
- iso-27001
- control_id
- A.8.19
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- 2022
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- UC-CONFIG-05 — Permit only authorized software installation and use maps_to CM-11 — User-installed Software
- framework
- nist-800-53
- control_id
- CM-11
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- Rev. 5
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- UC-CONFIG-05 — Permit only authorized software installation and use maps_to CM-10 — Software Usage Restrictions
- framework
- nist-800-53
- control_id
- CM-10
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- Rev. 5
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- UC-CONFIG-05 — Permit only authorized software installation and use mitigates Uncontrolled copying to removable media / unmanaged software installs
- strength
- primary
- rationale
- Restricting installs to authorized/approved software with allowlisting and anti-malware directly prevents unmanaged, untested software installs and malicious code.
- UC-CONFIG-05 — Permit only authorized software installation and use mitigates Use of unlicensed, counterfeit or pirated software
- strength
- primary
- rationale
- Sourcing approved software from trusted sources and tracking installs against license entitlements directly prevents unlicensed or pirated software use.
- Security Control Assessment & POA&M Remediation tests UC-CONFIG-05 — Permit only authorized software installation and use
- ISO 27001 Stage 2 Annex A Controls Audit tests UC-CONFIG-05 — Permit only authorized software installation and use