NIST 800-53 r5 · Controls catalogue · Family CM
CM-10Software Usage Restrictions
Use software and associated documentation in accordance with contract agreements and copyright laws; Track the use of software and associated documentation protected by quantity licenses to control copying and distribution; and Control and document the use of peer-to-peer file sharing technology to ensure that this capability is not used for the unauthorized distribution, display, performance, or reproduction of copyrighted work.
Last updated: 21 August 2026 07:11 UTC
Implementations targeting this control (0)
- No implementations targeting this control yet.
ATT&CK techniques this control mitigates (9)
- T1546.008 Accessibility Features Privilege Escalation, Persistence
- T1546.013 PowerShell Profile Privilege Escalation, Persistence
- T1550.001 Application Access Token Lateral Movement
- T1553 Subvert Trust Controls Defense Impairment
- T1553.004 Install Root Certificate Defense Impairment
- T1559 Inter-Process Communication Execution
- T1559.002 Dynamic Data Exchange Execution
- T1685 Disable or Modify Tools Defense Impairment
- T1688 Safe Mode Boot Defense Impairment
Weaknesses this control addresses (3)AI-assisted
CWEs ranked by how often they appear in real CVEs. The rationale describes how this control reduces exploitability of each weakness class.
| CWE | Name | CVEs | Why this control addresses it |
|---|---|---|---|
CWE-552 | Files or Directories Accessible to External Parties | 500+ | Controlling and documenting P2P file sharing prevents files and directories from being made accessible to external parties for unauthorized distribution. |
CWE-829 | Inclusion of Functionality from Untrusted Control Sphere | 300+ | Limiting P2P file sharing technology reduces inclusion of functionality or resources from untrusted external control spheres. |
CWE-506 | Embedded Malicious Code | 99 | Restricting software to licensed versions and controlling P2P prevents introduction of software containing embedded malicious code from unauthorized sources. |
Top CVEs where this control is the strongest mitigation
| CVE | Risk | CVSS | EPSS | Match |
|---|---|---|---|---|
| No CVEs annotated to this control yet — the per-CVE backfill is in progress. | ||||