Organizational Control: Software Usage Restrictions

Control ID: CM-10 Software Usage Restrictions Family: Configuration Management Source: NIST 800-53r4
Control: The organization:
  1. Uses software and associated documentation in accordance with contract agreements and copyright laws;
  2. Tracks the use of software and associated documentation protected by quantity licenses to control copying and distribution; and
  3. Controls and documents the use of peer-to-peer file sharing technology to ensure that this capability is not used for the unauthorized distribution, display, performance, or reproduction of copyrighted work.
Supplemental Guidance:
Software license tracking can be accomplished by manual methods (e.g.,simple spreadsheets) or automated methods (e.g., specialized tracking applications) depending on organizational needs.

Related Controls: AC-17, CM-8, SC-7
Control Enhancements: N/A
References: N/A
Mechanisms:
Protocol Implementation Conformance Statements: N/A