← CM-2

Automation Support for Accuracy and Currency

LOW ✓ MODERATE ✓ HIGH
1 Overlay 3 Related Controls
Graph
Export ▾

Requirements NIST SOURCE

Maintain the currency, completeness, accuracy, and availability of the baseline configuration of the system using [automated mechanisms].

Discussion (NIST Supplemental Guidance)

Automated mechanisms that help organizations maintain consistent baseline configurations for systems include configuration management tools, hardware, software, firmware inventory tools, and network management tools. Automated tools can be used at the organization level, mission and business process level, or system level on workstations, servers, notebook computers, network components, or mobile devices. Tools can be used to track version numbers on operating systems, applications, types of software installed, and current patch levels. Automation support for accuracy and currency can be satisfied by the implementation of CM-8(2) for organizations that combine system component inventory and baseline configuration activities.

Implementation Guidance

Engineering Interpretation

Original engineering commentary written for this explorer — not NIST source text and not authoritative guidance.

No engineering interpretation has been authored for CM-2(2) yet. This section is architected to receive it — see the Requirements and Assessment sections above for the authoritative NIST source content in the meantime.

Assessment

NIST SP 800-53A REV 5.2.0

Assessment Objectives

  1. automated mechanisms for maintaining baseline configuration of the system are defined;
  2. the currency of the baseline configuration of the system is maintained using <CM-02(02)_ODP automated mechanisms>;
  3. the completeness of the baseline configuration of the system is maintained using <CM-02(02)_ODP automated mechanisms>;
  4. the accuracy of the baseline configuration of the system is maintained using <CM-02(02)_ODP automated mechanisms>;
  5. the availability of the baseline configuration of the system is maintained using <CM-02(02)_ODP automated mechanisms>.

Examine

[SELECT FROM: Configuration management policy; procedures addressing the baseline configuration of the system; configuration management plan; system design documentation; system architecture and configuration documentation; system configuration settings and associated documentation; system component inventory; configuration change control records; system security plan; other relevant documents or records].

Interview

[SELECT FROM: Organizational personnel with configuration management responsibilities; organizational personnel with information security responsibilities; system/network administrators].

Test

[SELECT FROM: Organizational processes for managing baseline configurations; automated mechanisms implementing baseline configuration maintenance].

Overlays

Showing the OT/ICS overlay for the parent control CM-2 — see the CM-2(2) entries within each baseline below.

OT/ICS Overlay SP 800-82r3

NIST SP 800-82r3 Appendix F, Table 22. Blank baseline means the control/control enhancement is not selected in that initial OT baseline.

LOW

  • Base control: Included (matches standard baseline)

MODERATE

  • Base control: Included (matches standard baseline)
  • Included: (2) (3) (7)

HIGH

  • Base control: Included (matches standard baseline)
  • Included: (2) (3) (7)

STIGs & CCIs

No STIG checks or CCI mappings are currently loaded for CM-2(2). This section is architected to display, per product: STIG ID, Finding ID, Severity, Title, Description, Check, Fix, CCI, and NIST control mapping — but nothing is populated here until a real DISA STIG/CCI dataset is ingested.

Learn more about STIG/CCI integration →

Evidence

Potential Evidence — Derived

Categorized from the SP 800-53A "Examine"/"Test" artifact list above by keyword — not an authoritative NIST evidence list.

Policy

  • system security plan

Configuration

  • Configuration management policy
  • procedures addressing the baseline configuration of the system
  • configuration management plan
  • system design documentation
  • system architecture and configuration documentation
  • system configuration settings and associated documentation
  • system component inventory
  • configuration change control records

Testing

  • Organizational processes for managing baseline configurations
  • automated mechanisms implementing baseline configuration maintenance

Other Records

  • other relevant documents or records