NIST 800-171 · Configuration Management

Requirement 3.4.8

SPRS weight
SPRS weight: 5
POA&M eligibility
Not POA&M-eligible
Assessment objectives
3 assessment objectives

Official requirement text

Apply deny-by-exception (blacklisting) policy to prevent the use of unauthorized software or deny-all, permit-by-exception (whitelisting) policy to allow the execution of authorized software.

Assessment objectives

Assessors don’t evaluate the requirement as one sentence; they walk these objectives one by one. Each must be met for the requirement to score.

  1. 3.4.8[a]a policy specifying whether whitelisting or blacklisting is to be implemented is specified.
  2. 3.4.8[b]the software allowed to execute under whitelisting or denied use under blacklisting is specified.
  3. 3.4.8[c]whitelisting to allow the execution of authorized software or blacklisting to prevent the use of unauthorized software is implemented as specified.

Inside Valontir, this requirement carries a full plain-English guide: what it asks in normal words, what good looks like in a small shop, the evidence an assessor accepts, the common gaps that cost points, and a plain reading of every assessment objective shown above. See it in a demo.