Configuration Settings

✓ LOW ✓ MODERATE ✓ HIGH
2 Enhancements 1 Overlay 28 Related Controls
Graph
Export ▾

Requirements NIST SOURCE

Discussion (NIST Supplemental Guidance)

Configuration settings are the parameters that can be changed in the hardware, software, or firmware components of the system that affect the security and privacy posture or functionality of the system. Information technology products for which configuration settings can be defined include mainframe computers, servers, workstations, operating systems, mobile devices, input/output devices, protocols, and applications. Parameters that impact the security posture of systems include registry settings; account, file, or directory permission settings; and settings for functions, protocols, ports, services, and remote connections. Privacy parameters are parameters impacting the privacy posture of systems, including the parameters required to satisfy other privacy controls. Privacy parameters include settings for access controls, data processing preferences, and processing and retention permissions. Organizations establish organization-wide configuration settings and subsequently derive specific configuration settings for systems. The established settings become part of the configuration baseline for the system. Common secure configurations (also known as security configuration checklists, lockdown and hardening guides, and security reference guides) provide recognized, standardized, and established benchmarks that stipulate secure configuration settings for information technology products and platforms as well as instructions for configuring those products or platforms to meet operational requirements. Common secure configurations can be developed by a variety of organizations, including information technology product developers, manufacturers, vendors, federal agencies, consortia, academia, industry, and other organizations in the public and private sectors. Implementation of a common secure configuration may be mandated at the organization level, mission and business process level, system level, or at a higher level, including by a regulatory agency. Common secure configurations include the United States Government Configuration Baseline USGCB and security technical implementation guides (STIGs), which affect the implementation of CM-6 and other controls such as AC-19 and CM-7 . The Security Content Automation Protocol (SCAP) and the defined standards within the protocol provide an effective method to uniquely identify, track, and control configuration settings.

Enhancements NIST SOURCE

CM-6(1) Automated Management, Application, and Verification LOW MODERATE ✓ HIGH

Manage, apply, and verify configuration settings for [system components] using [organization-defined automated mechanisms].

Discussion

Automated tools (e.g., hardening tools, baseline configuration tools) can improve the accuracy, consistency, and availability of configuration settings information. Automation can also provide data aggregation and data correlation capabilities, alerting mechanisms, and dashboards to support risk-based decision-making within the organization.

Open full page for CM-6(1) →
CM-6(2) Respond to Unauthorized Changes LOW MODERATE ✓ HIGH

Take the following actions in response to unauthorized changes to [configuration settings]: [actions].

Discussion

Responses to unauthorized changes to configuration settings include alerting designated organizational personnel, restoring established configuration settings, or—in extreme cases—halting affected system processing.

Open full page for CM-6(2) →
CM-6(3) Unauthorized Change Detection WITHDRAWN

Withdrawn. Incorporated into SI-7.

CM-6(4) Conformance Demonstration WITHDRAWN

Withdrawn. Incorporated into CM-4.

Implementation Guidance

Engineering Interpretation

Original engineering commentary written for this explorer — not NIST source text and not authoritative guidance.

No engineering interpretation has been authored for CM-6 yet. This section is architected to receive it — see the Requirements and Assessment sections above for the authoritative NIST source content in the meantime.

Assessment

NIST SP 800-53A REV 5.2.0

Assessment Objectives

  1. common secure configurations to establish and document configuration settings for components employed within the system are defined;
  2. system components for which approval of deviations is needed are defined;
  3. operational requirements necessitating approval of deviations are defined;
  4. configuration settings that reflect the most restrictive mode consistent with operational requirements are established and documented for components employed within the system using <CM-06_ODP[01] common secure configurations>;
  5. the configuration settings documented in CM-06a are implemented;
  6. any deviations from established configuration settings for <CM-06_ODP[02] system components> are identified and documented based on <CM-06_ODP[03] operational requirements>;
  7. any deviations from established configuration settings for <CM-06_ODP[02] system components> are approved;
  8. changes to the configuration settings are monitored in accordance with organizational policies and procedures;
  9. changes to the configuration settings are controlled in accordance with organizational policies and procedures.

Examine

[SELECT FROM: Configuration management policy; procedures addressing configuration settings for the system; configuration management plan; system design documentation; system configuration settings and associated documentation; common secure configuration checklists; system component inventory; evidence supporting approved deviations from established configuration settings; change control records; system data processing and retention permissions; system audit records; system security plan; privacy plan; other relevant documents or records].

Interview

[SELECT FROM: Organizational personnel with security configuration management responsibilities; organizational personnel with privacy configuration management responsibilities; organizational personnel with information security and privacy responsibilities; system/network administrators].

Test

[SELECT FROM: Organizational processes for managing configuration settings; mechanisms that implement, monitor, and/or control system configuration settings; mechanisms that identify and/or document deviations from established configuration settings].

Overlays

OT/ICS Overlay SP 800-82r3

NIST SP 800-82r3 Appendix F, Table 22. Blank baseline means the control/control enhancement is not selected in that initial OT baseline.

LOW

  • Base control: Included (matches standard baseline)

MODERATE

  • Base control: Included (matches standard baseline)

HIGH

  • Base control: Included (matches standard baseline)
  • Included: (1) (2)

STIGs & CCIs

No STIG checks or CCI mappings are currently loaded for CM-6. This section is architected to display, per product: STIG ID, Finding ID, Severity, Title, Description, Check, Fix, CCI, and NIST control mapping — but nothing is populated here until a real DISA STIG/CCI dataset is ingested.

Learn more about STIG/CCI integration →

Evidence

Potential Evidence — Derived

Categorized from the SP 800-53A "Examine"/"Test" artifact list above by keyword — not an authoritative NIST evidence list.

Policy

  • system security plan
  • privacy plan

Configuration

  • Configuration management policy
  • procedures addressing configuration settings for the system
  • configuration management plan
  • system design documentation
  • system configuration settings and associated documentation
  • common secure configuration checklists
  • system component inventory
  • evidence supporting approved deviations from established configuration settings

Testing

  • Organizational processes for managing configuration settings
  • mechanisms that implement, monitor, and/or control system configuration settings
  • mechanisms that identify and/or document deviations from established configuration settings

Other Records

  • change control records
  • system data processing and retention permissions
  • system audit records
  • other relevant documents or records