Baseline Configuration
✓ LOW ✓ MODERATE ✓ HIGHRequirements NIST SOURCE
Requirement Context
This element is part of CM-2 — Baseline Configuration. See the Assessment section below for the related SP 800-53A examine/interview/test procedures. No engineering interpretation has been authored for this control yet.
- 1.[frequency];
- 2.When required due to [circumstances] ; and
- 3.When system components are installed or upgraded.
Requirement Context
This element is part of CM-2 — Baseline Configuration. See the Assessment section below for the related SP 800-53A examine/interview/test procedures. No engineering interpretation has been authored for this control yet.
Discussion (NIST Supplemental Guidance)
Baseline configurations for systems and system components include connectivity, operational, and communications aspects of systems. Baseline configurations are documented, formally reviewed, and agreed-upon specifications for systems or configuration items within those systems. Baseline configurations serve as a basis for future builds, releases, or changes to systems and include security and privacy control implementations, operational procedures, information about system components, network topology, and logical placement of components in the system architecture. Maintaining baseline configurations requires creating new baselines as organizational systems change over time. Baseline configurations of systems reflect the current enterprise architecture.
Enhancements NIST SOURCE
CM-2(1) Reviews and Updates WITHDRAWN
Withdrawn. Incorporated into CM-2.
CM-2(2) Automation Support for Accuracy and Currency LOW ✓ MODERATE ✓ HIGH
Maintain the currency, completeness, accuracy, and availability of the baseline configuration of the system using [automated mechanisms].
Discussion
Automated mechanisms that help organizations maintain consistent baseline configurations for systems include configuration management tools, hardware, software, firmware inventory tools, and network management tools. Automated tools can be used at the organization level, mission and business process level, or system level on workstations, servers, notebook computers, network components, or mobile devices. Tools can be used to track version numbers on operating systems, applications, types of software installed, and current patch levels. Automation support for accuracy and currency can be satisfied by the implementation of CM-8(2) for organizations that combine system component inventory and baseline configuration activities.
CM-2(3) Retention of Previous Configurations LOW ✓ MODERATE ✓ HIGH
Retain [number] of previous versions of baseline configurations of the system to support rollback.
Discussion
Retaining previous versions of baseline configurations to support rollback include hardware, software, firmware, configuration files, configuration records, and associated documentation.
CM-2(4) Unauthorized Software WITHDRAWN
Withdrawn. Incorporated into CM-7(4).
CM-2(5) Authorized Software WITHDRAWN
Withdrawn. Incorporated into CM-7(5).
CM-2(6) Development and Test Environments LOW MODERATE HIGH
Maintain a baseline configuration for system development and test environments that is managed separately from the operational baseline configuration.
Discussion
Establishing separate baseline configurations for development, testing, and operational environments protects systems from unplanned or unexpected events related to development and testing activities. Separate baseline configurations allow organizations to apply the configuration management that is most appropriate for each type of configuration. For example, the management of operational configurations typically emphasizes the need for stability, while the management of development or test configurations requires greater flexibility. Configurations in the test environment mirror configurations in the operational environment to the extent practicable so that the results of the testing are representative of the proposed changes to the operational systems. Separate baseline configurations do not necessarily require separate physical environments.
CM-2(7) Configure Systems and Components for High-risk Areas LOW ✓ MODERATE ✓ HIGH
- (a) Issue [systems or system components] with [configurations] to individuals traveling to locations that the organization deems to be of significant risk; and
- (b) Apply the following controls to the systems or components when the individuals return from travel: [controls].
Discussion
When it is known that systems or system components will be in high-risk areas external to the organization, additional controls may be implemented to counter the increased threat in such areas. For example, organizations can take actions for notebook computers used by individuals departing on and returning from travel. Actions include determining the locations that are of concern, defining the required configurations for the components, ensuring that components are configured as intended before travel is initiated, and applying controls to the components after travel is completed. Specially configured notebook computers include computers with sanitized hard drives, limited applications, and more stringent configuration settings. Controls applied to mobile devices upon return from travel include examining the mobile device for signs of physical tampering and purging and reimaging disk drives. Protecting information that resides on mobile devices is addressed in the MP (Media Protection) family.
Implementation Guidance
Original engineering commentary written for this explorer — not NIST source text and not authoritative guidance.
No engineering interpretation has been authored for CM-2 yet. This section is architected to receive it — see the Requirements and Assessment sections above for the authoritative NIST source content in the meantime.
Assessment
Assessment Objectives
- the frequency of baseline configuration review and update is defined;
- the circumstances requiring baseline configuration review and update are defined;
- a current baseline configuration of the system is developed and documented;
- a current baseline configuration of the system is maintained under configuration control;
- the baseline configuration of the system is reviewed and updated <CM-02_ODP[01] frequency>;
- the baseline configuration of the system is reviewed and updated when required due to <CM-02_ODP[02] circumstances>;
- the baseline configuration of the system is reviewed and updated when system components are installed or upgraded.
Examine
[SELECT FROM: Configuration management policy; procedures addressing the baseline configuration of the system; configuration management plan; enterprise architecture documentation; system design documentation; system security plan; privacy plan; system architecture and configuration documentation; system configuration settings and associated documentation; system component inventory; change control records; other relevant documents or records].
Interview
[SELECT FROM: Organizational personnel with configuration management responsibilities; organizational personnel with information security and privacy responsibilities; system/network administrators].
Test
[SELECT FROM: Organizational processes for managing baseline configurations; mechanisms supporting configuration control of the baseline configuration].
Overlays
STIGs & CCIs
No STIG checks or CCI mappings are currently loaded for CM-2. This section is architected to display, per product: STIG ID, Finding ID, Severity, Title, Description, Check, Fix, CCI, and NIST control mapping — but nothing is populated here until a real DISA STIG/CCI dataset is ingested.
Learn more about STIG/CCI integration →Evidence
Categorized from the SP 800-53A "Examine"/"Test" artifact list above by keyword — not an authoritative NIST evidence list.
Policy
- system security plan
- privacy plan
Configuration
- Configuration management policy
- procedures addressing the baseline configuration of the system
- configuration management plan
- enterprise architecture documentation
- system design documentation
- system architecture and configuration documentation
- system configuration settings and associated documentation
- system component inventory
Testing
- Organizational processes for managing baseline configurations
- mechanisms supporting configuration control of the baseline configuration
Other Records
- change control records
- other relevant documents or records