Fedramp system Security Plan (ssp) High Baseline Template


CM-7 (5) Control Enhancement (H)



Download 1.2 Mb.
Page174/478
Date16.12.2020
Size1.2 Mb.
#54609
1   ...   170   171   172   173   174   175   176   177   ...   478
FedRAMP-SSP-High-Baseline-Template
FedRAMP-SSP-High-Baseline-Template, North Carolina Summary Table of Ecoregion Characteristics

CM-7 (5) Control Enhancement (H)


The organization:

  1. Identifies [Assignment: organization-defined software programs authorized to execute on the information system];

  2. Employs a deny-all, permit-by-exception policy to allow the execution of authorized software programs on the information system; and

  3. Reviews and updates the list of authorized software programs [FedRAMP Assignment: at least quarterly or when there is a change].



CM-7 (5)

Control Summary Information

Responsible Role:

Parameter CM-7 (5)(a):

Parameter CM-7 (5)(c):

Implementation Status (check all that apply):

Implemented

☐ Partially implemented

Planned

☐ Alternative implementation

Not applicable

Control Origination (check all that apply):

☐ Service Provider Corporate

☐ Service Provider System Specific

☐ Service Provider Hybrid (Corporate and System Specific)

☐ Configured by Customer (Customer System Specific)

☐ Provided by Customer (Customer System Specific)

☐ Shared (Service Provider and Customer Responsibility)

☐ Inherited from pre-existing FedRAMP Authorization for Click here to enter text. ,



CM-7 (5) What is the solution and how is it implemented?

Part a




Part b




Part c






Download 1.2 Mb.

Share with your friends:
1   ...   170   171   172   173   174   175   176   177   ...   478




The database is protected by copyright ©ininet.org 2024
send message

    Main page