{"data":{"id":"CM-10","name":"Software Usage Restrictions","family":"CM","family_name":"Configuration Management","withdrawn":false,"description":"a. Use software and associated documentation in accordance with contract agreements and copyright laws;\nb. Track the use of software and associated documentation protected by quantity licenses to control copying and distribution; and\nc. Control and document the use of peer-to-peer file sharing technology to ensure that this capability is not used for the unauthorized distribution, display, performance, or reproduction of copyrighted work.","supplemental_guidance":"Software license tracking can be accomplished by manual or automated methods, depending on organizational needs. Examples of contract agreements include software license agreements and non-disclosure agreements.","enhancements":[{"id":"CM-10(01)","name":"Open-source Software","statement":"Establish the following restrictions on the use of open-source software: [Assignment: organization-defined restrictions].","baselines":[]}],"baseline_low":true,"baseline_moderate":true,"baseline_high":true,"nist_800_53":{"rev5":{"id":"CM-10","name":"Software Usage Restrictions","description":"a. Use software and associated documentation in accordance with contract agreements and copyright laws;\nb. Track the use of software and associated documentation protected by quantity licenses to control copying and distribution; and\nc. Control and document the use of peer-to-peer file sharing technology to ensure that this capability is not used for the unauthorized distribution, display, performance, or reproduction of copyrighted work.","discussion":"Software license tracking can be accomplished by manual or automated methods, depending on organizational needs. Examples of contract agreements include software license agreements and non-disclosure agreements.","related_controls":["AC-17","AU-06","CM-07","CM-08","PM-30","SC-07"],"baseline_low":true,"baseline_moderate":true,"baseline_high":true,"baseline_privacy":false,"new_in_rev5":false,"changes_from_rev4":"No significant changes from Rev 4."}},"compliance_mappings":{"iso_27001_2022":["A.5.32","A.8.9"],"iso_27002_2022":["5.37"],"cobit_2019":["BAI10"],"pci_dss_v4":[],"nist_csf_2":["DE.CM-03","DE.CM-09","ID.AM-02","PR.PS-01"],"cis_controls_v8":["CIS 2","CIS 2.1","CIS 2.4"],"soc2_tsc":[],"finos_ccc":[],"iso_42001_2023":[],"iec_62443":[],"asd_e8":[],"nis2":[],"apra_cps_234":[],"mas_trm":[],"pra_op_resilience":[],"bsi_grundschutz":[],"anssi":[],"osfi_b13":[],"finma_circular":[],"gdpr":[],"dora":[],"bio2":["5.37"],"rbi_csf":["Annex1.2"],"fisc":[],"lgpd_bcb":[],"hkma_tme1":[],"mlps_2":[],"dnb_good_practice":[],"cra":[],"swift_cscf":[],"qatar_nia":["OS"],"uae_ia":["T7"],"cbe_csf":["CTO-7"],"bot_cyber":["Ch2.1"],"ecb_croe":["CROE.2.3.4"],"ffiec_is":["II.C.13(e)"],"sebi_cscrf":["PR.ES","PR.IP"],"cmmc_2":["CM"],"nerc_cip":[],"nrc_73_54":[],"tsa_psd":[],"ieee_1686":[],"ferc_cip":[],"doe_c2m2":[],"api_1164":[],"awia":[],"iaea_nss":[],"pci_pts":[],"fips_140":[],"cbest":[],"tiber_eu":[],"pci_hsm":[],"common_criteria":[],"isae_3402":[],"fca_sysc_13":[],"fda_21_cfr_11":[],"fda_cyber":[],"hitrust_csf":[],"iso_27799":[],"lloyds_ms":["MS8.4"],"naic_ds":[],"nhs_dspt":[],"pra_ss1_23":[],"solvency_ii":[],"owasp_masvs_v2":[],"csa_ccm_v4":[],"csa_aicm":[],"ccss_v9":[],"mica":[],"basel_sco60":[],"bssc":[],"sec_custody_digital":[],"dpdpa":[]},"attack_techniques":[{"id":"T1553","name":"Subvert Trust Controls","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Software usage restrictions that require approved, licensed software prevent adversaries from installing unauthorized applications that subvert trust controls or introduce unsigned, untrusted code."},{"id":"T1559","name":"Inter-Process Communication","tactics":["execution"],"mapping_type":"mitigates","mapping_rationale":"Software usage restrictions limiting which applications can be installed and executed constrain the inter-process communication surface available to adversaries for cross-application code execution."},{"id":"T1546.008","name":"Accessibility Features","tactics":["persistence","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Software usage restrictions prevent installation of unauthorized accessibility tools that adversaries might substitute for legitimate accessibility features to establish persistent backdoor access."},{"id":"T1546.013","name":"PowerShell Profile","tactics":["persistence","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Restricting software usage to approved PowerShell installations and profiles prevents adversaries from deploying modified PowerShell environments with malicious profile scripts for persistence."},{"id":"T1550.001","name":"Application Access Token","tactics":["defense-evasion","lateral-movement"],"mapping_type":"mitigates","mapping_rationale":"Software usage restrictions on OAuth application registration and API client installations limit which applications can request and use access tokens, preventing token theft through unauthorized apps."},{"id":"T1553.004","name":"Install Root Certificate","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Software usage restrictions prevent installation of unauthorized certificate management tools that adversaries could use to install rogue root certificates for trust subversion."},{"id":"T1559.002","name":"Dynamic Data Exchange","tactics":["execution"],"mapping_type":"mitigates","mapping_rationale":"Software restrictions on applications supporting Dynamic Data Exchange limit the DDE attack surface by ensuring only approved, security-hardened applications with disabled DDE are deployed."},{"id":"T1562.006","name":"Indicator Blocking","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Software usage restrictions prevent installation of unauthorized tools that could block security telemetry indicators, ensuring only approved applications that respect security monitoring are deployed."},{"id":"T1562.009","name":"Safe Mode Boot","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Software restrictions on boot configuration tools prevent adversaries from using unauthorized utilities to configure Safe Mode boot options that disable security software during startup."}],"metadata":{"last_reviewed":"2026-10-03","review_notes":"Generated from NIST SP 800-53 Rev 5 with compliance mappings from framework-coverage data 2026-10-03: iso_27001_2022 A.5.32 added from NIST's SP 800-53 Rev 5 to ISO/IEC 27001:2022 crosswalk (OLIR entry 155), which OSA's mapping now takes as its base. 2026-10-03: nist_csf_2 DE.CM-03, DE.CM-09, PR.PS-01 added from NIST's CSF 2.0 to SP 800-53 Rev 5.2.0 crosswalk (OLIR entry 186), which OSA's mapping now takes as its base.","mapping_status":"complete"},"function":"preventative","used_by_patterns":[]}}