800-53|CM-10

Title

SOFTWARE USAGE RESTRICTIONS

Description

The organization:

Supplemental

Software license tracking can be accomplished by manual methods (e.g., simple spreadsheets) or automated methods (e.g., specialized tracking applications) depending on organizational needs.

Reference Item Details

Related: AC-17,CM-8,SC-7

Category: CONFIGURATION MANAGEMENT

Family: CONFIGURATION MANAGEMENT

Priority: P2

Baseline Impact: LOW,MODERATE,HIGH

Audit Items

View all Reference Audit Items

NamePluginAudit Name
1.1 Ensure the appropriate MongoDB software version/patches are installedMongoDBCIS MongoDB 5 L1 DB v1.2.0
1.1 Ensure the appropriate MongoDB software version/patches are installedMongoDBCIS MongoDB 6 L1 DB v1.1.0
1.1.1.5 Ensure mounting of hfsplus filesystems is disabled - lsmodUnixCIS Debian 8 Server L1 v2.0.2
1.1.1.5 Ensure mounting of hfsplus filesystems is disabled - lsmodUnixCIS Debian 8 Workstation L1 v2.0.2
1.1.1.5 Ensure mounting of hfsplus filesystems is disabled - modprobeUnixCIS Debian 8 Server L1 v2.0.2
1.1.1.5 Ensure mounting of hfsplus filesystems is disabled - modprobeUnixCIS Debian 8 Workstation L1 v2.0.2
1.1.3.4.5 Configure 'Devices: Prevent users from installing printer drivers'WindowsCIS Windows 8 L1 v1.0.0
1.1.4.1.1 Ensure 'Add-on Management' is set to 'Enabled'WindowsCIS Microsoft Office Enterprise v1.1.0 L1
1.1.4.1.2 Ensure 'Bind to object' is set to 'Enabled'WindowsCIS Microsoft Office Enterprise v1.1.0 L1
1.1.4.1.5 Ensure 'Information Bar' is set to 'Enabled'WindowsCIS Microsoft Office Enterprise v1.1.0 L1
1.1.4.1.11 Ensure 'Restrict ActiveX Install' is set to 'Enabled'WindowsCIS Microsoft Office Enterprise v1.1.0 L1
1.1.4.1.14 Ensure 'Scripted Window Security Restrictions' is set to 'Enabled'WindowsCIS Microsoft Office Enterprise v1.1.0 L1
1.1.5 Ensure noexec option set on /tmp partitionUnixCIS Google Container-Optimized OS L1 Server v1.1.0
1.1.7 Ensure noexec option set on /var partitionUnixCIS Google Container-Optimized OS L2 Server v1.1.0
1.1.9 Ensure noexec option set on /var/tmp partitionUnixCIS Debian 8 Server L1 v2.0.2
1.1.9 Ensure noexec option set on /var/tmp partitionUnixCIS Debian 8 Workstation L1 v2.0.2
1.1.12 Ensure noexec option set on /dev/shm partitionUnixCIS Google Container-Optimized OS L1 Server v1.1.0
1.1.16 Ensure noexec option set on /dev/shm partitionUnixCIS Debian 8 Workstation L1 v2.0.2
1.1.16 Ensure noexec option set on /dev/shm partitionUnixCIS Debian 8 Server L1 v2.0.2
1.1.19 Ensure noexec option set on removable media partitionsUnixCIS Debian 8 Server L1 v2.0.2
1.1.19 Ensure noexec option set on removable media partitionsUnixCIS Debian 8 Workstation L1 v2.0.2
1.3.1 Ensure 'Allow read access via the File System API on these sites' is set to 'Disabled'WindowsCIS Microsoft Edge L2 v2.0.0
1.3.1 Ensure 'Block Flash activation in Office documents' is set to 'Enabled: Block all activation'WindowsCIS Microsoft Office Enterprise v1.1.0 L1
1.3.4 Ensure 'Control use of JavaScript JIT' is set to 'Enabled: Do not allow any site to run JavaScript JIT'WindowsCIS Microsoft Edge L2 v2.0.0
1.3.5 Ensure 'Control use of the File System API for reading' is set to 'Enabled: Don't allow any site to request read access to files and directories'WindowsCIS Microsoft Edge L2 v2.0.0
1.3.6 Ensure 'Control use of the File System API for writing' is set to 'Enabled: Don't allow any site to request write access to files and directories'WindowsCIS Microsoft Edge L1 v2.0.0
1.3.7 Ensure 'Control use of the Web Bluetooth API' is set to 'Enabled: Do not allow any site to request access to Bluetooth'WindowsCIS Microsoft Edge L2 v2.0.0
1.3.8 Ensure 'Control use of the WebHID API' is set to 'Enabled: Do not allow any site to request access to HID devices via the WebHID API'WindowsCIS Microsoft Edge L2 v2.0.0
1.5.1 Ensure 'Configure users ability to override feature flags' is set to 'Enabled: Prevent users from overriding feature flags'WindowsCIS Microsoft Edge L1 v2.0.0
1.6.1 Ensure 'Configure extension management settings' is set to 'Enabled: *'WindowsCIS Microsoft Edge L2 v2.0.0
1.11 Ensure 'User consent for applications' is set to 'Do not allow user consent'microsoft_azureCIS Microsoft Azure Foundations v2.0.0 L1
1.12 Ensure 'User consent for applications' Is Set To 'Allow for Verified Publishers'microsoft_azureCIS Microsoft Azure Foundations v2.0.0 L2
1.13 Ensure that 'Users can add gallery apps to My Apps' is set to 'No'microsoft_azureCIS Microsoft Azure Foundations v2.0.0 L1
1.14 Ensure That 'Users Can Register Applications' Is Set to 'No'microsoft_azureCIS Microsoft Azure Foundations v2.0.0 L1
1.14.1 Ensure 'Enable startup boost' is set to 'Disabled'WindowsCIS Microsoft Edge L1 v2.0.0
1.25 Ensure 'Allow features to download assets from the Asset Delivery Service' is set to 'Disabled'WindowsCIS Microsoft Edge L2 v2.0.0
1.26 Ensure 'Allow file selection dialogs' is set to 'Disabled'WindowsCIS Microsoft Edge L2 v2.0.0
1.35 Ensure 'Allow managed extensions to use the Enterprise Hardware Platform API' is set to 'Disabled'WindowsCIS Microsoft Edge L1 v2.0.0
1.41 Ensure 'Allow remote debugging' is set to 'Disabled'WindowsCIS Microsoft Edge L1 v2.0.0
1.43 Ensure 'Allow unconfigured sites to be reloaded in Internet Explorer mode' is set to 'Disabled'WindowsCIS Microsoft Edge L2 v2.0.0
1.49 Ensure 'AutoLaunch Protocols Component Enabled' is set to 'Disabled'WindowsCIS Microsoft Edge L2 v2.0.0
1.67 Ensure 'Control communication with the Experimentation and Configuration Service' is set to 'Enabled: Disable communication with the Experimentation and Configuration Service'WindowsCIS Microsoft Edge L1 v2.0.0
1.69 Ensure 'Control use of the Serial API' is set to 'Enable: Do not allow any site to request access to serial ports via the Serial API'WindowsCIS Microsoft Edge L2 v2.0.0
1.78 Ensure 'Enable browser legacy extension point blocking' is set to 'Enabled'WindowsCIS Microsoft Edge L1 v2.0.0
1.113 Ensure 'Show the Reload in Internet Explorer mode button in the toolbar' is set to 'Disabled'WindowsCIS Microsoft Edge L1 v2.0.0
11.3 Ensure the httpd_t Type is Not in Permissive ModeUnixCIS Apache HTTP Server 2.4 L2 v2.1.0
11.3 Ensure the httpd_t Type is Not in Permissive ModeUnixCIS Apache HTTP Server 2.4 L2 v2.1.0 Middleware
11.4 Ensure Only the Necessary SELinux Booleans are EnabledUnixCIS Apache HTTP Server 2.4 L2 v2.1.0
11.4 Ensure Only the Necessary SELinux Booleans are EnabledUnixCIS Apache HTTP Server 2.4 L2 v2.1.0 Middleware
12.1 Ensure the AppArmor Framework Is EnabledUnixCIS Apache HTTP Server 2.4 L2 v2.1.0 Middleware