800-53|CM-10

Title

SOFTWARE USAGE RESTRICTIONS

Description

The organization:

Supplemental

Software license tracking can be accomplished by manual methods (e.g., simple spreadsheets) or automated methods (e.g., specialized tracking applications) depending on organizational needs.

Reference Item Details

Related: AC-17,CM-8,SC-7

Category: CONFIGURATION MANAGEMENT

Family: CONFIGURATION MANAGEMENT

Priority: P2

Baseline Impact: LOW,MODERATE,HIGH

Audit Items

View all Reference Audit Items

NamePluginAudit Name
1.1 Ensure the appropriate MongoDB software version/patches are installedUnixCIS MongoDB 7 v1.2.0 L1 Unix
1.1 Ensure the appropriate MongoDB software version/patches are installedWindowsCIS MongoDB 7 v1.2.0 L1 Windows
1.1 Ensure the appropriate MongoDB software version/patches are installedUnixCIS MongoDB 8 v1.0.0 L1 Unix
1.1 Ensure the appropriate MongoDB software version/patches are installedMongoDBCIS MongoDB 5 L1 DB v1.2.0
1.1 Ensure the appropriate MongoDB software version/patches are installedUnixCIS MongoDB 6 v1.2.0 L1 MongoDB
1.1 Ensure the appropriate MongoDB software version/patches are installedWindowsCIS MongoDB 6 v1.2.0 L1 MongoDB
1.1 Ensure the appropriate MongoDB software version/patches are installedWindowsCIS MongoDB 8 v1.0.0 L1 Windows
1.1.1.1 (L1) Ensure 'Allow add-on installs from websites' is set to 'Disabled'WindowsCIS Mozilla Firefox ESR GPO v1.0.0 L1
1.1.1.1 (L1) Ensure 'Block Flash activation in Office documents' is set to 'Enabled: Block all activation'WindowsCIS Microsoft Intune for Office v1.1.0 L1
1.1.1.5 Ensure mounting of hfsplus filesystems is disabled - lsmodUnixCIS Debian 8 Server L1 v2.0.2
1.1.1.5 Ensure mounting of hfsplus filesystems is disabled - lsmodUnixCIS Debian 8 Workstation L1 v2.0.2
1.1.1.5 Ensure mounting of hfsplus filesystems is disabled - modprobeUnixCIS Debian 8 Server L1 v2.0.2
1.1.1.5 Ensure mounting of hfsplus filesystems is disabled - modprobeUnixCIS Debian 8 Workstation L1 v2.0.2
1.1.2.11.3 Ensure noexec option set on removable media partitionsUnixCIS Red Hat Enterprise Linux 8 STIG v2.0.0 L1 Workstation
1.1.2.11.3 Ensure noexec option set on removable media partitionsUnixCIS Red Hat Enterprise Linux 8 STIG v2.0.0 STIG
1.1.2.11.3 Ensure noexec option set on removable media partitionsUnixCIS Red Hat Enterprise Linux 8 STIG v2.0.0 L1 Server
1.1.3.4.5 Configure 'Devices: Prevent users from installing printer drivers'WindowsCIS Windows 8 L1 v1.0.0
1.1.4.1.1 Ensure 'Add-on Management' is set to 'Enabled'WindowsCIS Microsoft Office Enterprise v1.2.0 L1
1.1.4.1.2 Ensure 'Bind to object' is set to 'Enabled'WindowsCIS Microsoft Office Enterprise v1.2.0 L1
1.1.4.1.5 Ensure 'Information Bar' is set to 'Enabled'WindowsCIS Microsoft Office Enterprise v1.2.0 L1
1.1.4.1.11 Ensure 'Restrict ActiveX Install' is set to 'Enabled'WindowsCIS Microsoft Office Enterprise v1.2.0 L1
1.1.4.1.14 Ensure 'Scripted Window Security Restrictions' is set to 'Enabled'WindowsCIS Microsoft Office Enterprise v1.2.0 L1
1.1.5 Ensure noexec option set on /tmp partitionUnixCIS Google Container-Optimized OS v1.2.0 L1 Server
1.1.7 Ensure noexec option set on /var partitionUnixCIS Google Container-Optimized OS v1.2.0 L2 Server
1.1.9 Ensure noexec option set on /var/tmp partitionUnixCIS Debian 8 Server L1 v2.0.2
1.1.9 Ensure noexec option set on /var/tmp partitionUnixCIS Debian 8 Workstation L1 v2.0.2
1.1.12 Ensure noexec option set on /dev/shm partitionUnixCIS Google Container-Optimized OS v1.2.0 L1 Server
1.1.12.1 (L1) Ensure 'Activate Flash on websites' is set to 'Disabled'WindowsCIS Mozilla Firefox ESR GPO v1.0.0 L1
1.1.16 Ensure noexec option set on /dev/shm partitionUnixCIS Debian 8 Server L1 v2.0.2
1.1.16 Ensure noexec option set on /dev/shm partitionUnixCIS Debian 8 Workstation L1 v2.0.2
1.1.18.7 (L1) Ensure 'extensions.blocklist.enabled' is set to 'Enabled'WindowsCIS Mozilla Firefox ESR GPO v1.0.0 L1
1.1.19 Ensure noexec option set on removable media partitionsUnixCIS Debian 8 Server L1 v2.0.2
1.1.19 Ensure noexec option set on removable media partitionsUnixCIS Debian 8 Workstation L1 v2.0.2
1.1.23.1 (L1) Ensure 'Extension Recommendations' is set to 'Disabled'WindowsCIS Mozilla Firefox ESR GPO v1.0.0 L1
1.2.1 (L2) Ensure 'AllowedExtensions' is configuredWindowsCIS Visual Studio Code GPO v1.0.0 L2
1.2.5.1.1 (L1) Ensure 'Add-on Management' is set to 'Enabled'WindowsCIS Microsoft Intune for Office v1.1.0 L1
1.2.5.1.2 (L1) Ensure 'Bind to object' is set to 'Enabled'WindowsCIS Microsoft Intune for Office v1.1.0 L1
1.2.5.1.5 (L1) Ensure 'Information Bar' is set to 'Enabled'WindowsCIS Microsoft Intune for Office v1.1.0 L1
1.2.5.1.11 (L1) Ensure 'Restrict ActiveX Install' is set to 'Enabled'WindowsCIS Microsoft Intune for Office v1.1.0 L1
1.2.5.1.14 (L1) Ensure 'Scripted Window Security Restrictions' is set to 'Enabled'WindowsCIS Microsoft Intune for Office v1.1.0 L1
1.10.1 (L1) Ensure 'Blocks external extensions from being installed' is set to 'Enabled'WindowsCIS Microsoft Edge v4.0.0 L1
1.10.1 (L1) Ensure 'Blocks external extensions from being installed' is set to 'Enabled'WindowsCIS Microsoft Intune for Edge v1.0.0 L1
1.10.2 (L2) Ensure 'Configure extension management settings' is set to 'Enabled: { '*': {'installation_mode': 'blocked' }}'WindowsCIS Microsoft Edge v4.0.0 L2
1.10.2 (L2) Ensure 'Configure extension management settings' is set to 'Enabled: { '*': {'installation_mode': 'blocked' }}'WindowsCIS Microsoft Intune for Edge v1.0.0 L2
1.27 Ensure that no 3rd party keyboards are installedMDMAirWatch - CIS Google Android v1.6.0 L1
1.27 Ensure that no 3rd party keyboards are installedMDMMobileIron - CIS Google Android v1.6.0 L1
1.107 (L1) Ensure 'Enable upload files from mobile in Microsoft Edge desktop' is set to 'Disabled'WindowsCIS Microsoft Intune for Edge v1.0.0 L1
1.108 (L1) Ensure 'Enable upload files from mobile in Microsoft Edge desktop' is set to 'Disabled'WindowsCIS Microsoft Edge v4.0.0 L1
1.126 (L1) Ensure 'Show the Reload in Internet Explorer mode button in the toolbar' is set to 'Disabled'WindowsCIS Microsoft Intune for Edge v1.0.0 L1
1.127 (L1) Ensure 'Show the Reload in Internet Explorer mode button in the toolbar' is set to 'Disabled'WindowsCIS Microsoft Edge v4.0.0 L1