Skip to content

CM-7.5: Authorized Software — Allow-by-exception

An OSCAL Control

Statement

    • (a)

      Identify ;

    • (b)

      Employ a deny-all, permit-by-exception policy to allow the execution of authorized software programs on the system; and

    • (c)

      Review and update the list of authorized software programs .