Use technical controls to ensure that only authorized software libraries, such as specific .dll, .ocx,
and .so files, are allowed to load into a system process. Block unauthorized libraries from loading into
a system process. Reassess bi-annually, or more frequently.
The organization implements an allowlist for approved libraries by requiring digital signatures from trusted certificate authorities for all libraries.
The organization uses application whitelisting to ensure only approved libraries load and configures security policies to block unapproved libraries.
Unmanaged installations of software on computers can lead to vulnerabilities and security breaches.
The organization should determine what types of software or updates each user can install. The instructions may include e.g. the following guidelines:
Our organization has defined policies in place to prevent or at least detect the use of unauthorized programs.