The organization defines the frequency on which it will update the list of unauthorized software programs.
No STIG checks reference this CCI.