DE.CM-5.1: The organization shall define acceptable and unacceptable mobile code and mobile code technologies; and authorize, monitor, and control the use of mobile code within the system.
Mobile code includes any program, application, or content that can be transmitted across a network (e.g., embedded in an email, document, or website) and executed on a remote system. Mobile code technologies include for example Java applets, JavaScript, HTML5, WebGL, and VBScript.
Decisions regarding the use of mobile code in organizational systems should be based on the potential for the code to cause damage to the systems if used maliciously. Usage restrictions and implementation guidance should apply to the selection and use of mobile code installed.
Documentation Maturity
Implementation Maturity
Description
The organization shall define acceptable and unacceptable mobile code and mobile code technologies; and authorize, monitor, and control the use of mobile code within the system.