What users can install is governed and monitored.
What it actually means
Govern what users can install themselves — through policy plus technical controls (removing local admin, an approved-software process, monitoring for unauthorized installs). It pairs with application control above.
Pass or fail — an assessor needs a "yes" to each
- A policy governs user-installed software.
- Technical controls limit installs (e.g., no local admin / managed app catalog).
- Installs are monitored.
What to have ready
- User-software policy
- Local-admin removal / managed install configuration
- Software inventory / monitoring
Where teams trip up
- Everyone is a local admin installing freely
- No visibility into what got installed
- Policy with no monitoring
See where this control puts your score
Run all 110 requirements free in about 10 minutes — or draft your SSP language for this control. No signup.
Calculate your SPRS score →Draft your SSP language →Connected requirements
More in Configuration Management (3.4)
3.4.1 — Inventory and baseline your systems3.4.2 — Enforce secure configuration settings3.4.3 — Control and log changes3.4.4 — Check changes before you make them3.4.5 — Restrict who can make changes3.4.6 — Least functionality3.4.7 — Block nonessential ports and services3.4.8 — Control which software can run