NIST 800-53 r5 · Controls catalogue · Family CM
CM-11User-installed Software
Establish {{ insert: param, cm-11_odp.01 }} governing the installation of software by users; Enforce software installation policies through the following methods: {{ insert: param, cm-11_odp.02 }} ; and Monitor policy compliance {{ insert: param, cm-11_odp.03 }}.
Last updated: 22 August 2026 07:11 UTC
Implementations targeting this control (0)
- No implementations targeting this control yet.
ATT&CK techniques this control mitigates (33)
- T1021.005 VNC Lateral Movement
- T1059 Command and Scripting Interpreter Execution
- T1059.006 Python Execution
- T1072 Software Deployment Tools Execution, Lateral Movement
- T1176 Software Extensions Persistence
- T1195 Supply Chain Compromise Initial Access
- T1195.001 Compromise Software Dependencies and Development Tools Initial Access
- T1195.002 Compromise Software Supply Chain Initial Access
- T1218 System Binary Proxy Execution Stealth
- T1218.001 Compiled HTML File Stealth
- T1218.002 Control Panel Stealth
- T1218.003 CMSTP Stealth
- T1218.004 InstallUtil Stealth
- T1218.005 Mshta Stealth
- T1218.008 Odbcconf Stealth
- T1218.009 Regsvcs/Regasm Stealth
- T1218.012 Verclsid Stealth
- T1218.013 Mavinject Stealth
- T1218.014 MMC Stealth
- T1505 Server Software Component Persistence
- T1505.001 SQL Stored Procedures Persistence
- T1505.002 Transport Agent Persistence
- T1505.004 IIS Components Persistence
- T1543 Create or Modify System Process Persistence, Privilege Escalation
- T1543.001 Launch Agent Persistence, Privilege Escalation
- T1543.002 Systemd Service Persistence, Privilege Escalation
- T1543.003 Windows Service Persistence, Privilege Escalation
- T1543.004 Launch Daemon Persistence, Privilege Escalation
- T1547.013 XDG Autostart Entries Persistence, Privilege Escalation
- T1550.001 Application Access Token Lateral Movement
- T1564.009 Resource Forking Stealth
- T1569 System Services Execution
- T1569.001 Launchctl Execution
Weaknesses this control addresses (4)AI-assisted
CWEs ranked by how often they appear in real CVEs. The rationale describes how this control reduces exploitability of each weakness class.
| CWE | Name | CVEs | Why this control addresses it |
|---|---|---|---|
CWE-284 | Improper Access Control | 6,900+ | This control establishes and enforces policies that restrict which users can install software and what software is permitted. |
CWE-829 | Inclusion of Functionality from Untrusted Control Sphere | 300+ | Enforcing installation policies prevents users from including functionality obtained from untrusted control spheres. |
CWE-494 | Download of Code Without Integrity Check | 200+ | Policies can require integrity verification of software prior to installation, reducing risks from unverified downloads. |
CWE-506 | Embedded Malicious Code | 99 | The control prevents users from installing software that contains embedded malicious code. |
Top CVEs where this control is the strongest mitigation
| CVE | Risk | CVSS | EPSS | Match |
|---|---|---|---|---|
CVE-2024-56346 UPD | 7.6 | 10.0 | 0.0109 | partial |
CVE-2025-36250 | 7.5 | 10.0 | 0.0067 | partial |
CVE-2024-56347 UPD | 6.9 | 9.6 | 0.0089 | partial |
CVE-2025-36251 | 6.8 | 9.6 | 0.0054 | partial |
CVE-2025-1950 UPD | 6.3 | 9.3 | 0.0019 | partial |
CVE-2024-25021 UPD | 6.2 | 8.4 | 0.0027 | partial |
CVE-2025-0160 UPD | 6.1 | 8.1 | 0.0050 | partial |
CVE-2024-32004 UPD | 6.0 | 8.1 | 0.0135 | partial |
CVE-2025-23385 UPD | 5.3 | 7.8 | 0.0013 | partial |
CVE-2026-26945 | 4.0 | 5.3 | 0.0018 | partial |
CVE-2025-46370 | 2.7 | 3.3 | 0.0011 | partial |
CVE-2026-29046 UPD | 6.2 | 8.2 | 0.0039 | partial |