CCI-001773
CCI-001773 Definition
The organization identifies the organization-defined software programs authorized to execute on the information system.
Status | |
Type | CheckType.policy |
Master Assessment Datasheet
Implementation Guidance
The organization being inspected/assessed must define and document software programs that are authorized to execute on the information system.
Validation Procedures
The organization conducting the inspection/assessment obtains and examines the documented list of software programs that are authorized to execute to ensure that list is defined.
Compelling Evidence
1.) Approved software list 2.) Rules for approval of software program usage