Independent DIB implementation resource — not affiliated with or endorsed by the U.S. Department of WarView the official DoW campaign ↗
3.4.9OFFICIAL STATEMENT BELOWDERIVED REQUIREMENTPENDING NIST SME REVIEW

3.4.9User-installed software control

3.4 Configuration Management · NIST SP 800-171 Rev. 2 · The heading label is this site's navigational shorthand; the official language is the statement below.

Independent interpretation

What this requirement is after

What users install on their own machines is controlled and monitored — because every self-installed utility, browser extension, and free PDF converter is unvetted code inside your boundary. This is where shadow IT and CUI collide.

Across revisions

Withdrawn as a standalone requirement in Rev. 3 (the 03.04.09 slot is marked withdrawn); user-installed software falls under the allow-by-exception software policy of 03.04.08.

Mapped practices

Brilliant at the Basics practices that support this requirement

Doing the work

Implementation considerations and evidence

Implementation considerationsIndependent guidance — tailor to your environment
  • Remove standing local-administrator rights; most user installation risk disappears with them.
  • Offer a sanctioned path — a self-service catalog or a fast request process — so the legitimate need that drove the install has somewhere better to go.
  • Monitor installed software through endpoint telemetry and reconcile against the approved list on a cadence.
What operating evidence looks likeRecords worth retaining, not a submission checklist
  • Policy and technical settings governing user installation rights
  • Installed-software reports reconciled against the approved list
Artifacts

Templates and worksheets with a mapped relationship

No artifact in the library names this requirement yet. The library index groups everything by category and practice.

The other revision

Where this lands in Rev. 3

Provenance

Sources and review status

Primary sourcesNIST SP 800-171 Rev. 2 — Protecting CUI in Nonfederal Systems · NIST SP 800-171A — Assessing Security Requirements for CUI
Review statusPending NIST SME review
Content version1.0
Updated