# CM-10 Software Usage Restrictions

NIST SP 800-53 control. Family: CM Configuration Management. Function: preventative. Baselines: low, moderate, high. Mapping licence: CC BY-SA 4.0.

Statement: a. Use software and associated documentation in accordance with contract agreements and copyright laws; b. Track the use of software and associated documentation protected by quantity licenses to control copying and distribution; and c. Control and document the use of peer-to-peer file sharing technology to ensure that this capability is not used for the unauthorized distribution, display, performance, or reproduction of copyrighted work.
Guidance: Software license tracking can be accomplished by manual or automated methods, depending on organizational needs. Examples of contract agreements include software license agreements and non-disclosure agreements.

## Enhancements (1)
- CM-10(01) Open-source Software
Each enhancement's statement: /api/v1/controls/CM-10?fields=enhancements

## Clauses by framework (16 frameworks)
- iso_27001_2022: A.5.32, A.8.9. OSA's own, not in NIST's crosswalk: A.8.9
- iso_27002_2022: 5.37
- cobit_2019: BAI10
- nist_csf_2: DE.CM-03, DE.CM-09, ID.AM-02, PR.PS-01. OSA's own, not in NIST's crosswalk: ID.AM-02
- cis_controls_v8: CIS 2, CIS 2.1, CIS 2.4
- bio2: 5.37
- rbi_csf: Annex1.2
- qatar_nia: OS
- uae_ia: T7
- cbe_csf: CTO-7
- bot_cyber: Ch2.1
- ecb_croe: CROE.2.3.4
- ffiec_is: II.C.13(e)
- sebi_cscrf: PR.ES, PR.IP
- cmmc_2: CM
- lloyds_ms: MS8.4
OSA's mapping for iso_27001_2022 and nist_csf_2 takes NIST's published crosswalk as its base. A clause not marked as OSA's own is in that crosswalk.

## More
- This control as JSON, with guidance and ATT&CK techniques: /api/v1/controls/CM-10
- Clauses only: /api/v1/controls/CM-10?fields=mappings
- Page for people: /controls/cm-10/
- Found an error? Open an issue at https://github.com/opensecurityarchitecture/osa-data/issues with the id, what OSA says and what the source says.
