The organization:
- CM-6a.
- Establishes and documents configuration settings for information technology products employed within the information system using [Assignment: organization-defined security configuration checklists] that reflect the most restrictive mode consistent with operational requirements;
- CM-6b.
- Implements the configuration settings;
- CM-6c.
- Identifies, documents, and approves any deviations from established configuration settings for [Assignment: organization-defined information system components] based on [Assignment: organization-defined operational requirements]; and
- CM-6d.
- Monitors and controls changes to the configuration settings in accordance with organizational policies and procedures.
Configuration settings are the set of parameters that can be changed in hardware, software, or firmware components of the information system that affect the security posture and/or functionality of the system. Information technology products for which security-related configuration settings can be defined include, for example, mainframe computers, servers (e.g., database, electronic mail, authentication, web, proxy, file, domain name), workstations, input/output devices (e.g., scanners, copiers, and printers), network components (e.g., firewalls, routers, gateways, voice and data switches, wireless access points, network appliances, sensors), operating systems, middleware, and applications. Security-related parameters are those parameters impacting the security state of information systems including the parameters required to satisfy other security control requirements. Security-related parameters include, for example: (i) registry settings; (ii) account, file, directory permission settings; and (iii) settings for functions, ports, protocols, services, and remote connections. Organizations establish organization-wide configuration settings and subsequently derive specific settings for information systems. The established settings become part of the systems configuration baseline.
Common secure configurations (also referred to as security configuration checklists, lockdown and hardening guides, security reference guides, security technical implementation guides) provide recognized, standardized, and established benchmarks that stipulate secure configuration settings for specific information technology platforms/products and instructions for configuring those information system components to meet operational requirements. Common secure configurations can be developed by a variety of organizations including, for example, information technology product developers, manufacturers, vendors, consortia, academia, industry, federal agencies, and other organizations in the public and private sectors. Common secure configurations include the United States Government Configuration Baseline (USGCB) which affects the implementation of CM-6 and other controls such as AC-19 and CM-7. The Security Content Automation Protocol (SCAP) and the defined standards within the protocol (e.g., Common Configuration Enumeration) provide an effective method to uniquely identify, track, and control configuration settings. OMB establishes federal policy on configuration requirements for federal information systems.
- CM-6.1 - CCI-000363
- The organization defines security configuration checklists to be used to establish and document configuration settings for the information system technology products employed.
- CM-6.2 - CCI-000364
- The organization establishes configuration settings for information technology products employed within the information system using organization-defined security configuration checklists.
- CM-6.3 - CCI-000365
- The organization documents configuration settings for information technology products employed within the information system using organization-defined security configuration checklists that reflect the most restrictive mode consistent with operational requirements.
- CM-6.4 - CCI-001588
- The organization-defined security configuration checklists reflect the most restrictive mode consistent with operational requirements.
- CM-6.5 - CCI-000366
- The organization implements the security configuration settings.
- CM-6.6 - CCI-000367
- The organization identifies any deviations from the established configuration settings for organization-defined information system components based on organization-defined operational requirements.
- CM-6.7 - CCI-000368
- The organization documents any deviations from the established configuration settings for organization-defined information system components based on organization-defined operational requirements.
- CM-6.8 - CCI-000369
- The organization approves any deviations from the established configuration settings for organization-defined information system components based on organization-defined operational requirements.
- CM-6.9 - CCI-001755
- The organization defines the information system components for which any deviation from the established configuration settings are to be identified, documented and approved.
- CM-6.10 - CCI-001756
- The organization defines the operational requirements on which the configuration settings for the organization-defined information system components are to be based.
- CM-6.11 - CCI-001502
- The organization monitors changes to the configuration settings in accordance with organizational policies and procedures.
- CM-6.12 - CCI-001503
- The organization controls changes to the configuration settings in accordance with organizational policies and procedures.
-
AC-19
-
Access Control For Mobile Devices
-
CM-2
-
Baseline Configuration
-
CM-3
-
Configuration Change Control
-
CM-7
-
Least Functionality
-
SI-4
-
Information System Monitoring