The organization maintains a list of software programs authorized to execute on the information system.
No STIG checks reference this CCI.