NIST 800-171 Controls · Configuration Management
CM.2.008 — Apply Deny-by-Exception Policy to Prevent Use of Unauthorized Software
Apply deny-by-exception (blacklisting) policy to prevent the use of unauthorized software or deny-all, permit-by-exception (whitelisting) policy to allow the execution of authorized software.
What CM.2.008 means in plain English
This is the formal policy underpinning CM.2.007. You need a written policy that explicitly states your approach: either (a) block specific known bad software and allow everything else (blacklisting—easier to start with), or (b) only allow specifically approved software and block everything else (whitelisting—more secure, recommended by DoD). Most small shops start with blacklisting and then move to whitelisting. Document which approach you use, why, and how it is enforced. Assessors want to see the policy document, not just the technical control.
The assessment question
“Is there a written software use policy that explicitly adopts either a deny-by-exception (blacklist) or deny-all-permit-by-exception (whitelist) approach, and is this policy enforced by technical controls with evidence of both?”
How to implement CM.2.008
- Write a one-page "Software Use Policy" that states: (a) the approach taken (blacklist or whitelist), (b) the list of prohibited software categories (peer-to-peer file sharing, torrent clients, unapproved remote access tools, cryptocurrency mining software, games), (c) the list of approved software (if whitelist approach), and (d) the consequences of violating the policy.
- For a blacklist approach: use Windows Defender Application Control (WDAC) or Group Policy > Software Restriction Policies to block specific known-bad applications by hash, certificate, or path. Maintain a "Prohibited Software List" updated when new threats are identified (reference CISA Known Exploited Vulnerabilities catalog at cisa.gov/known-exploited-vulnerabilities-catalog).
- For a whitelist approach (recommended): use AppLocker or WDAC configured in "deny-all, permit-by-exception" mode as described in CM.2.007. The approved software inventory from CM.2.007 becomes your permit list.
- Align the written policy with your technical enforcement: if your Group Policy enforces a whitelist, your written policy should say "deny-all, permit-by-exception." Assessors will verify that the policy and technical controls are consistent.
- Review and update the software use policy annually or when new contract requirements are received. Document the review with a date and signature.
Evidence your assessor will ask for
- Written Software Use Policy specifying blacklist or whitelist approach, prohibited software categories, and enforcement mechanism
- Technical control configuration (WDAC, AppLocker, or SRP policy export) consistent with the written policy
- Evidence of policy review date and approver signature
- Prohibited software list (if blacklist approach) or approved software list (if whitelist approach)
- Evidence that the policy has been communicated to all users (e.g., included in annual awareness training)
Does AI prompt monitoring help with this control? Honestly, no.
CM.2.008 is met through the remediation steps above, not through AI traffic controls — an AI prompt firewall neither satisfies nor substitutes for it. We map AI monitoring only to the controls it genuinely evidences (flow control, boundary protection, audit, and incident support); for the full picture of where it does help, see the mapping guide linked below.
Full mapping: which 800-171 controls AI prompt monitoring evidences →
More Configuration Management controls
Establish and Maintain Baseline Configurations
CM.2.002Establish and Enforce Security Configuration Settings
CM.2.003Track, Review, Approve, and Log Changes to Systems
CM.2.004Analyze Security Impact of Changes Prior to Implementation
CM.2.005Define and Enforce Access Restrictions for Configuration Changes
CM.2.006Employ Principle of Least Functionality
Score yourself against all 110 controls
The free ShieldReady assessment walks every NIST 800-171 requirement, computes your SPRS score, and shows exactly which gaps cost the most points.