1. Home
  2. 3.4.8 Apply Deny-by-Exception (Blacklisting) or Permit-by-Exception (Whitelisting) Policies

3.4.8 Apply Deny-by-Exception (Blacklisting) or Permit-by-Exception (Whitelisting) Policies

3.4.8 Apply deny-by-exception (blacklist) policy to prevent the use of unauthorized software or deny-all, permit-by-exception (whitelisting) policy to allow the execution of authorized software.

To go back to the NIST 800-171 Controls page click here.

Guides

Example Tools

Additional Lessons Learned

Vendor Documentation

Updated on April 7, 2026
Was this article helpful?
Need Support?
Can’t find the answer you’re looking for? Don’t worry we’re here to help!
Contact Support