You allow only approved software (or block known-bad) — by policy and tooling.
What it actually means
You control what software executes — either by blocking unauthorized software (deny-by-exception) or, better, allowing only approved software (allowlisting / deny-all-permit-by-exception). Application control (AppLocker, WDAC, or an EDR feature) is how this is enforced.
Pass or fail — an assessor needs a "yes" to each
- A software-execution policy exists (allowlist preferred, or blocklist).
- It's enforced with tooling (AppLocker/WDAC/EDR), not just policy.
- Unauthorized software is actually prevented from running.
What to have ready
- Application-control configuration (AppLocker/WDAC/EDR)
- Allowlist or blocklist policy
- Test/enforcement evidence
Where teams trip up
- Policy on paper with no enforcement
- Users free to install and run anything
- Allowlist defined but in audit-only mode
See where this control puts your score
Run all 110 requirements free in about 10 minutes — or draft your SSP language for this control. No signup.
Calculate your SPRS score →Draft your SSP language →Connected requirements
More in Configuration Management (3.4)
3.4.1 — Inventory and baseline your systems3.4.2 — Enforce secure configuration settings3.4.3 — Control and log changes3.4.4 — Check changes before you make them3.4.5 — Restrict who can make changes3.4.6 — Least functionality3.4.7 — Block nonessential ports and services3.4.9 — Control user-installed software