The organization must have list of approved applications, and application sources, that are allowed to be used on the organization's endpoint devices.
The organization should, if possible, execute management of approved software using automation for example with policies from mobile device management system.
Only software approved by the organization can be run on the devices. The organization should: