CM-11 Configuration Management

User-Installed Software

High Risk Moderate Medium Cost

CM-11 requires establishing policies governing the installation of software by users; enforcing those policies through technical methods when supported; and monitoring policy compliance on a defined frequency. Clinicians installing remote-support tools, browser extensions, or personal cloud sync on ePHI workstations is a persistent healthcare threat path for ransomware and unauthorized disclosure.

Control Objective

Prevent unauthorized software from being installed or executed on systems that access ePHI — through policy, technical enforcement, and ongoing monitoring.

Implementation Guidance

  1. Publish an allowed/denied software policy for clinical and corporate endpoints that handle ePHI.
  2. Enforce with application allowlisting, mobile device management, or removal of local admin rights on standard workstations.
  3. Provide a fast request path for legitimate clinical tools so users do not bypass controls.
  4. Block common high-risk categories: unsanctioned remote access, personal sync (consumer Dropbox-class), cracking tools, and unknown browser extensions where feasible.
  5. Monitor for new local admin installs, unsigned executables, and policy exceptions; review frequently.
  6. Cover VDI golden images and physician BYOD/VDI scenarios with equivalent rules.
  7. Align exceptions with CM-3 change control and documented risk acceptance.
  8. Educate workforce (AT-2) on why shadow software endangers patient data and care devices.

Real-World Use Cases

How this control shows up in healthcare and HIPAA-covered environments.

Physician installs consumer screen-sharing

A doctor adds a free remote tool to a laptop with cached clinic mail and VPN. CM-11 technical blocks stop the install; an approved telehealth/support tool is offered instead.

Browser extension harvests portal sessions

Allowlisting and extension control under CM-11 prevent a malicious extension from riding on patient-portal admin browsers.

Quarterly software compliance scan

Monitoring finds a nursing station with a portable executable toolkit. Local admin rights are removed and the image is rebuilt — demonstrating CM-11 monitoring frequency.

Best Practices

  • Deny-by-default or strong allowlisting on ePHI endpoints.
  • Remove standing local admin for standard users.
  • Easy sanctioned software request workflow.
  • Regular compliance monitoring/reporting.
  • Cover VDI and privileged workstations.
  • Document exceptions with expiry dates.

Common Gaps & Violations

  • Policy exists; users still have local admin everywhere.
  • No monitoring for unauthorized installs.
  • Clinical exceptions never expire.
  • BYOD accessing ePHI with zero software controls.
  • Shadow IT remote tools widespread in clinics.

Required Documentation

  • User-installed software policy
  • Technical enforcement design (allowlist/MDM/admin rights)
  • Software request / exception process
  • Monitoring and compliance review evidence
  • Approved software catalog excerpts

How to Test & Validate

  1. Attempt unauthorized install on a standard clinical image; confirm block.
  2. Verify standard users lack local admin.
  3. Review latest compliance monitoring report.
  4. Sample exceptions for approval and expiry.
  5. Confirm VDI/gold image controls match policy.

Audit Considerations

Assessors ask how you stop unauthorized software on ePHI workstations. Policy without enforcement (local admin for all) fails CM-11 in practice.

HIPAA Mapping

How this NIST control supports HIPAA Security Rule expectations.

  • 164.308(a)(1) Risk Management — unauthorized software is a malware and disclosure risk to ePHI.
  • 164.312(a) Access Control — workstations should enforce policies that limit what users can run/install.
  • 164.308(a)(5) Security Awareness and Training — workforce must understand software installation rules.
  • 164.310(b) Workstation Use — policies for proper workstation use include authorized software/tools.

Compliance Tips

  • Pair CM-11 with CM-7 least functionality on clinical images.
  • Keep the approved catalog visible on the intranet with request buttons.
  • Report top unauthorized software attempts monthly to clinic leadership.

Frequently Asked Questions

Does CM-11 ban all user installs forever?

It requires a governing policy and enforcement. Some roles may install within approved catalogs; unmanaged free-for-all is out of bounds for ePHI endpoints.

How does CM-11 relate to CM-7?

CM-7 limits services/functions/components; CM-11 specifically governs user-driven software installation behavior and monitoring.

What about clinicians who need specialized apps quickly?

Offer a rapid vetted request path — friction that is too high drives dangerous workarounds.

References & Resources

  • NIST SP 800-53 Rev. 5 — CM-11
  • Related controls: CM-7, CM-2, CM-3, SI-3, SI-7, AC-6, AT-2

Need Help Implementing CM-11?

Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.