DKDavid Koran& Associates
Home The CMMC Guide Part III · Configuration Management CM.L2-3.4.9
The CMMC Guide · Configuration Management Family

CM.L2-3.4.9  User-Installed Software

Control and monitor user-installed software.

Family
Configuration ManagementCM, 9 requirements
Point Value
1Lower weight, but not POA&M exempt
POA&M Eligible
YesOne-point requirement, may be deferred
Objectives
ThreePer NIST SP 800-171A

1Overview

CM.L2-3.4.9 closes the Configuration Management family by governing what users install. It requires that the organization control and monitor user-installed software, so that individuals cannot freely add software to systems and any installation is visible. It is a one-point requirement and may be deferred on a plan of action.

Software users install on their own, a browser extension, a utility, a personal application, can introduce vulnerabilities, malware, or unlicensed code that undermines the careful configuration around it. This control asks the organization to establish a policy for user-installed software, to control installation according to that policy, and to monitor for what is installed, so that the environment is not quietly reshaped by individual choices. It complements the execution control of 3.4.8 by governing the act of installation itself.

The requirement · NIST SP 800-171 Rev 2, 3.4.9

Control and monitor user-installed software.

The requirement pairs control with monitoring. To control is to set and enforce a policy on what users may install, often by limiting installation rights or requiring approval. To monitor is to have visibility of what actually gets installed, so that unauthorized software is noticed. Together they keep the software on systems governed rather than accumulating through individual initiative.

2The Assessment Objectives

NIST SP 800-171A decomposes 3.4.9 into three objectives: establish a policy, control installation, and monitor installation.

[a]

A policy for controlling the installation of software by users is established. The organization has decided what users may install.

MeetsA policy defining what software users may install and under what conditions.
FailsNo policy exists, so users install whatever they choose.
[b]

Installation of software by users is controlled based on the established policy. The policy is actually enforced.

MeetsUser installation is controlled, often by removing local admin rights or requiring approval.
FailsThe policy exists but users can still install anything.
[c]

Installation of software by users is monitored. The organization has visibility of what is installed.

MeetsInstalled software is monitored, so unauthorized additions are noticed.
FailsNo monitoring exists, so unauthorized software goes unseen.

The three objectives are a policy, its enforcement, and monitoring. The common gap is at objective [b], where a policy exists but users retain the rights to install freely, so the control is nominal. The assessor looks for installation actually controlled and monitored, not just a written policy.

3Failure Patterns

The failures are about free installation and policy without enforcement or visibility.

Users with local admin rights

Where users hold local administrator rights, they can install anything, so the policy cannot be enforced. Removing local admin rights or requiring approval is the usual way to control installation, and leaving broad rights fails objective [b].

Policy without control

A policy stating what may be installed, with nothing preventing other installations, leaves objective [b] unmet. Control has to be enforced technically, not just stated.

No monitoring of installed software

Without monitoring, unauthorized software installed despite the policy goes unnoticed. Objective [c] requires visibility of what is actually installed, often through inventory or endpoint tooling.

Shadow software accumulating

Over time, uncontrolled installation leaves systems full of software no one authorized, some outdated or risky. Controlling and monitoring installation keeps that accumulation from happening.

The common root
This control fails when users can install freely. Local admin rights, convenient for the user, mean the software on systems is shaped by individual choices rather than organizational policy, and unless installation is controlled and monitored, the environment drifts through additions no one reviewed.

4Ownership

This is an IT-owned technical control, closely tied to how user privileges are structured.

RoleResponsibility for this control
IT and system administratorEstablishes and enforces the installation policy, usually by limiting installation rights, and monitors what is installed. Owns the technical evidence.
Security or compliance leadConfirms installation is actually controlled and monitored, not just governed on paper.
Program leadReviews installed software periodically and retains the monitoring evidence.
See also: This control complements the execution policy of CM.L2-3.4.8, draws on the least privilege of AC.L2-3.1.5, and supports the least functionality of CM.L2-3.4.6.

5Tooling

The control is delivered by limiting installation rights and by monitoring installed software.

ObjectivesToolingWhat it provides
[a]User software installation policyThe defined rules for what users may install.
[b]Removal of local admin rights, approval workflows, managed app storesEnforcement that controls what users can install.
[c]Software inventory, endpoint monitoringVisibility of what is actually installed, so unauthorized additions are noticed.

The caveat is that control usually depends on limiting the rights that make free installation possible. A policy has little effect while users retain local admin rights, so removing those rights or gating installation is what enforces it, and monitoring catches what slips through. The assessor examines whether installation is actually controlled and monitored, so both have to be real.

6Evidence

The satisfied version of 3.4.9 shows a policy, enforced control, and monitoring of installation.

EvidenceWhat it demonstrates
Installation policyObjective [a]. The defined rules for user-installed software.
Privilege and control configurationObjective [b]. Enforcement limiting what users can install.
Software inventory or monitoringObjective [c]. Visibility of what is installed.

The evidence should show installation both controlled and monitored, resting on limited installation rights and software visibility. The policy paired with enforced control and monitoring is the clearest demonstration of the control.

Local admin rights let the environment reshape itself

When users can install freely, the software on systems is shaped by individual choices rather than policy, and this control asks for installation to be controlled and monitored. Limiting installation rights and gaining visibility of what is installed is part of the onsite readiness work this practice does.

Start CMMC Readiness or call 802-335-2662

7Sources

  1. NIST Special Publication 800-171 Rev 2, Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations, requirement 3.4.9. csrc.nist.gov
  2. NIST Special Publication 800-171A, Assessing Security Requirements for Controlled Unclassified Information, assessment objectives 3.4.9[a] through 3.4.9[c]. csrc.nist.gov
  3. 32 CFR 170.21, Plan of Action and Milestones Requirements, governing which requirements may remain open at a Level 2 assessment. ecfr.gov
← Previous in Configuration Management
CM.L2-3.4.8 · Application Allow and Deny Listing
Next: Identification and Authentication →
IA.L2-3.5.1 · Identify Users and Devices
About the Author
David W. Koran is a CyberAB Registered Practitioner Advanced and the author of The CMMC Decision, now in its second edition. He works onsite with defense contractors and their counsel, from the first leadership briefing through the pre-assessment review. Reach him at 802-335-2662 or dkoran@davidkoran.com.
Entry CM.L2-3.4.9 · Edition 2026.1 · Last reviewed July 12, 2026