1Overview
CM.L2-3.4.9 closes the Configuration Management family by governing what users install. It requires that the organization control and monitor user-installed software, so that individuals cannot freely add software to systems and any installation is visible. It is a one-point requirement and may be deferred on a plan of action.
Software users install on their own, a browser extension, a utility, a personal application, can introduce vulnerabilities, malware, or unlicensed code that undermines the careful configuration around it. This control asks the organization to establish a policy for user-installed software, to control installation according to that policy, and to monitor for what is installed, so that the environment is not quietly reshaped by individual choices. It complements the execution control of 3.4.8 by governing the act of installation itself.
Control and monitor user-installed software.
The requirement pairs control with monitoring. To control is to set and enforce a policy on what users may install, often by limiting installation rights or requiring approval. To monitor is to have visibility of what actually gets installed, so that unauthorized software is noticed. Together they keep the software on systems governed rather than accumulating through individual initiative.
2The Assessment Objectives
NIST SP 800-171A decomposes 3.4.9 into three objectives: establish a policy, control installation, and monitor installation.
A policy for controlling the installation of software by users is established. The organization has decided what users may install.
Installation of software by users is controlled based on the established policy. The policy is actually enforced.
Installation of software by users is monitored. The organization has visibility of what is installed.
The three objectives are a policy, its enforcement, and monitoring. The common gap is at objective [b], where a policy exists but users retain the rights to install freely, so the control is nominal. The assessor looks for installation actually controlled and monitored, not just a written policy.
3Failure Patterns
The failures are about free installation and policy without enforcement or visibility.
Users with local admin rights
Where users hold local administrator rights, they can install anything, so the policy cannot be enforced. Removing local admin rights or requiring approval is the usual way to control installation, and leaving broad rights fails objective [b].
Policy without control
A policy stating what may be installed, with nothing preventing other installations, leaves objective [b] unmet. Control has to be enforced technically, not just stated.
No monitoring of installed software
Without monitoring, unauthorized software installed despite the policy goes unnoticed. Objective [c] requires visibility of what is actually installed, often through inventory or endpoint tooling.
Shadow software accumulating
Over time, uncontrolled installation leaves systems full of software no one authorized, some outdated or risky. Controlling and monitoring installation keeps that accumulation from happening.
4Ownership
This is an IT-owned technical control, closely tied to how user privileges are structured.
| Role | Responsibility for this control |
|---|---|
| IT and system administrator | Establishes and enforces the installation policy, usually by limiting installation rights, and monitors what is installed. Owns the technical evidence. |
| Security or compliance lead | Confirms installation is actually controlled and monitored, not just governed on paper. |
| Program lead | Reviews installed software periodically and retains the monitoring evidence. |
5Tooling
The control is delivered by limiting installation rights and by monitoring installed software.
| Objectives | Tooling | What it provides |
|---|---|---|
| [a] | User software installation policy | The defined rules for what users may install. |
| [b] | Removal of local admin rights, approval workflows, managed app stores | Enforcement that controls what users can install. |
| [c] | Software inventory, endpoint monitoring | Visibility of what is actually installed, so unauthorized additions are noticed. |
The caveat is that control usually depends on limiting the rights that make free installation possible. A policy has little effect while users retain local admin rights, so removing those rights or gating installation is what enforces it, and monitoring catches what slips through. The assessor examines whether installation is actually controlled and monitored, so both have to be real.
6Evidence
The satisfied version of 3.4.9 shows a policy, enforced control, and monitoring of installation.
| Evidence | What it demonstrates |
|---|---|
| Installation policy | Objective [a]. The defined rules for user-installed software. |
| Privilege and control configuration | Objective [b]. Enforcement limiting what users can install. |
| Software inventory or monitoring | Objective [c]. Visibility of what is installed. |
The evidence should show installation both controlled and monitored, resting on limited installation rights and software visibility. The policy paired with enforced control and monitoring is the clearest demonstration of the control.
Local admin rights let the environment reshape itself
When users can install freely, the software on systems is shaped by individual choices rather than policy, and this control asks for installation to be controlled and monitored. Limiting installation rights and gaining visibility of what is installed is part of the onsite readiness work this practice does.
Start CMMC Readiness or call 802-335-26627Sources
- NIST Special Publication 800-171 Rev 2, Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations, requirement 3.4.9. csrc.nist.gov
- NIST Special Publication 800-171A, Assessing Security Requirements for Controlled Unclassified Information, assessment objectives 3.4.9[a] through 3.4.9[c]. csrc.nist.gov
- 32 CFR 170.21, Plan of Action and Milestones Requirements, governing which requirements may remain open at a Level 2 assessment. ecfr.gov