HomeControl Library › 3.4.8
3.4 Configuration Management5 pts

3.4.8 — Control which software can run

Apply deny-by-exception (blacklisting) policy to prevent the use of unauthorized software or deny-all, permit-by-exception (whitelisting) policy to allow the execution of authorized software.

You allow only approved software (or block known-bad) — by policy and tooling.

What it actually means

You control what software executes — either by blocking unauthorized software (deny-by-exception) or, better, allowing only approved software (allowlisting / deny-all-permit-by-exception). Application control (AppLocker, WDAC, or an EDR feature) is how this is enforced.

Pass or fail — an assessor needs a "yes" to each

What to have ready

Where teams trip up

See where this control puts your score

Run all 110 requirements free in about 10 minutes.

Calculate your SPRS score →

Connected requirements

← Back to the Control Library