NIST 800-171 Controls · Configuration Management
CM.2.007 — Restrict, Disable, or Prevent Use of Nonessential Programs
Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services.
What CM.2.007 means in plain English
This is the operational enforcement of the previous control—not just disabling things during setup, but actively preventing people from turning them back on or installing new nonessential programs over time. Use Windows AppLocker or Software Restriction Policies to create a whitelist of approved programs. If it is not on the list, Windows blocks it from running. For a machine shop this is very practical: your machinists should only be running your CAM software, your ERP, Microsoft Office, and a web browser—not unapproved software downloaded from the internet.
The assessment question
“Are there technical controls in place (such as application whitelisting or software restriction policies) that prevent users from running unauthorized or nonessential programs on systems that process CUI?”
How to implement CM.2.007
- Evaluate AppLocker (available on Windows 10/11 Enterprise and Education, and Windows Server) as your application whitelisting solution. If on Windows 10/11 Pro, use Software Restriction Policies (SRP) in Group Policy as a free alternative.
- Create an inventory of approved applications for each device type: standard workstation (CAM software, ERP/job management, Microsoft Office, approved browser), administrative workstation (same plus accounting software), IT admin workstation (same plus admin tools). This becomes your whitelist.
- Configure AppLocker or SRP: use the "Executable Rules" to allow only listed programs and block everything else. Start in "Audit Only" mode for 2 weeks to see what would be blocked (review AppLocker event log at Applications and Services Logs > Microsoft > Windows > AppLocker). Then switch to enforcement mode.
- Block known high-risk file types at the email gateway and web filter level: .exe, .bat, .ps1, .vbs attachments in email; downloads from software distribution sites. Microsoft 365 Defender (included in M365 Business Premium) can block malicious attachments automatically.
- Document the approved software list and the AppLocker/SRP configuration. Update the whitelist via the change management process (CM.2.003) whenever new approved software is added.
Evidence your assessor will ask for
- Approved software inventory (whitelist) for each device type
- AppLocker or SRP policy export/screenshot showing enforcement configuration
- AppLocker event log excerpt showing the policy is active and blocking unauthorized programs
- Written procedure for adding new approved software through the change management process
- Evidence that audit mode was run before enforcement to prevent business disruption
Does AI prompt monitoring help with this control? Honestly, no.
CM.2.007 is met through the remediation steps above, not through AI traffic controls — an AI prompt firewall neither satisfies nor substitutes for it. We map AI monitoring only to the controls it genuinely evidences (flow control, boundary protection, audit, and incident support); for the full picture of where it does help, see the mapping guide linked below.
Full mapping: which 800-171 controls AI prompt monitoring evidences →
More Configuration Management controls
Establish and Maintain Baseline Configurations
CM.2.002Establish and Enforce Security Configuration Settings
CM.2.003Track, Review, Approve, and Log Changes to Systems
CM.2.004Analyze Security Impact of Changes Prior to Implementation
CM.2.005Define and Enforce Access Restrictions for Configuration Changes
CM.2.006Employ Principle of Least Functionality
Score yourself against all 110 controls
The free ShieldReady assessment walks every NIST 800-171 requirement, computes your SPRS score, and shows exactly which gaps cost the most points.