CM-11: User-Installed Software
NIST Baseline: Low
DIR Required By: 01/20/2023
TAMUS Required By: 02/01/2024
Review Date: 09/01/2026
- All software installed on Tarleton-owned or operated computer systems used by faculty, staff, agents, or students in the conduct of university business must be appropriately licensed.
- For software having a licensing agreement, persons installing or authorizing the installation of software should be familiar with the terms of the agreement. Where feasible, the licensing agreement should be maintained in the department that operates the system on which the software is installed or through a license management agreement with a third party.
- In cases where this is not feasible, individuals or organizations should maintain sufficient documentation (e.g., End User License Agreements, purchase receipts) to validate that the software is appropriately licensed.
- Software shall not be copied or installed by any faculty, staff, agent, or student unless the licensing agreement specifically grants such a procedure.
- For instances in which the unit is the owner and/or custodian of the system hosting the software, the unit is responsible for monitoring user installation of software and ensuring compliance with this Control.
- New and/or updated/modified software should go through a software security and digital accessibility review prior to installation as per Tarleton Chief Information Security Officer (CISO) requirements where feasible, especially for software that processes and/or stores sensitive or high-impact information. Additional information on these reviews can be found in Control SA-3, System Development Life Cycle. Please contact the Tarleton Office of Innovative Technology Solutions (OITS) Security Team for additional information on software security reviews and more information on digital accessibility can be found on the Tarleton Digital Accessibility Review website.