CCI-001765
CCI-001765 Definition
Status | |
Type | CheckType.policy |
Master Assessment Datasheet
Implementation Guidance
The organization being inspected/assessed must define and document software programs not authorized to execute on the information system. For network capable software, the organization-defined list must include all software programs as defined IAW DoDI 8551.01. DoD has determined that a comprehensive list of unauthorized software programs is not appropriate to define at the Enterprise level.
Validation Procedures
The organization conducting the inspection/assessment obtains and examines the documented list of software programs not authorized to execute to ensure that list is defined. The organization conducting the inspection/assessment reviews the list to ensure that any network capable software is included IAW DoDI 8551.01. DoD has determined that a comprehensive list of unauthorized software programs is not appropriate to define at the Enterprise level.
Compelling Evidence
1.) Disapproved software list