// Level 3 · Controls

Configuration Management

NIST SP 800-53 Rev 5 Configuration Management controls.

CM-01Medium

Policy and Procedures

Develop, document, and disseminate to [parameter]:

CM-02Medium

Baseline Configuration

Develop, document, and maintain under configuration control, a current baseline configuration of the system; and

CM-03Medium

Configuration Change Control

Determine and document the types of changes to the system that are configuration-controlled;

CM-04Medium

Impact Analyses

Analyze changes to the system to determine potential security and privacy impacts prior to change implementation.

CM-05Medium

Access Restrictions for Change

Define, document, approve, and enforce physical and logical access restrictions associated with changes to the system.

CM-06Medium

Configuration Settings

Establish and document configuration settings for components employed within the system that reflect the most restrictive mode consistent with operational requirements using [parameter];

CM-07Medium

Least Functionality

Configure the system to provide only [parameter] ; and

CM-08Medium

System Component Inventory

Develop and document an inventory of system components that:

CM-09Medium

Configuration Management Plan

Develop, document, and implement a configuration management plan for the system that:

CM-10Medium

Software Usage Restrictions

Use software and associated documentation in accordance with contract agreements and copyright laws;

CM-11Medium

User-installed Software

Establish [parameter] governing the installation of software by users;

CM-12Medium

Information Location

Identify and document the location of [parameter] and the specific system components on which the information is processed and stored;

CM-13Medium

Data Action Mapping

Develop and document a map of system data actions.

CM-14Medium

Signed Components

Prevent the installation of [parameter] without verification that the component has been digitally signed using a certificate that is recognized and approved by the organization.