Frameworks / NIST Cybersecurity Framework 2.0 / NIST-CSF-PR.PS-01 NIST Cybersecurity Framework 2.0
PR - Protect
NIST Cybersecurity Framework 2.0 NIST-CSF-PR.PS-01: Configuration management practices are established and applied Configuration management practices are established and applied. Control from NIST Cybersecurity Framework 2.0 framework, domain: PR - Protect.
Maintained by Gerard Blokdyk · Verified against the published standard 31 May 2026 · Control text last updated 21 May 2026 What else in your programme already covers this This control maps to 227 controls across 77 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
1.2.1 1.2.1 Ruleset configuration standards for NSCs 1.2.5 1.2.5 Allowed services, protocols and ports justified 1.2.6 1.2.6 Security features for insecure services in use 1.2.7 1.2.7 Six-monthly review of NSC configurations 1.2.8 1.2.8 NSC configuration files secured and consistent 11.3.2 11.3.2 Quarterly ASV external vulnerability scans 2.2.1 2.2.1 System configuration standards maintained 2.2.2 2.2.2 Vendor default accounts managed 2.2.4 2.2.4 Only necessary functionality enabled 2.2.5 2.2.5 Insecure services, protocols or daemons secured 2.2.6 2.2.6 System security parameters configured against misuse 2.3.1 2.3.1 Wireless vendor defaults changed or confirmed secure 6.5.1 6.5.1 Change control procedure for production AM-2 Use only approved services ASBv3-GS-5 Define and implement security posture management strategy ASBv3-NS-7 Simplify network security configuration ASBv3-NS-8 Detect and disable insecure services and protocols ASBv3-PA-6 Use privileged access workstations ASBv3-PV-1 Define and establish secure configurations ASBv3-PV-3 Define and establish secure configurations for compute resources ASBv3-PV-4 Audit and enforce secure configurations for compute resources PV-2 Audit and enforce secure configurations CIS-12.3 Securely Manage Network Infrastructure CIS-13.5 Manage Access Control for Remote Assets CIS-16.7 Use Standard Hardening Configuration Templates for Application Infrastructure CIS-18.1 Establish and Maintain a Penetration Testing Program CIS-4.1 Establish and Maintain a Secure Configuration Process CIS-4.2 Establish and Maintain a Secure Configuration Process for Network Infrastructure CIS-4.6 Securely Manage Enterprise Assets and Software CIS-4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software CIS-7.3 Perform Automated Operating System Patch Management CM-2 Baseline Configuration CM-3 Configuration Change Control CM-5 Access Restrictions for Change CM-6 Configuration Settings CM-6(1) Automated Management, Application, and Verification CM-7 Least Functionality CM-7(1) Periodic Review CM-9 Configuration Management Plan CM-2 Baseline Configuration CM-3 Configuration Change Control CM-5 Access Restrictions for Change CM-6 Configuration Settings CM-6(1) Automated Management, Application, and Verification CM-7 Least Functionality CM-7(1) Periodic Review CM-9 Configuration Management Plan ASD37-01 Application control (Essential) ASD37-03 Configure Microsoft Office macro settings (Essential) ASD37-04 User application hardening (Essential) ASD37-09 OS generic exploit mitigation (Excellent) ASD37-10 Server application hardening (Very Good) ASD37-11 Operating system hardening (Very Good) ANSSI-HYG-12 Change Default Authentication Elements on Equipment and Services ANSSI-HYG-14 Apply a Minimum Security Level Across the Whole Estate ANSSI-HYG-16 Use a Centralised Management Tool to Standardise Security Policies ANSSI-HYG-17 Enable and Configure the Local Firewall on Workstations ANSSI-HYG-33 Adopt Security Policies Dedicated to Mobile Terminals C5-DEV-03 Policies for changes to information systems C5-OPS-16 Logging and Monitoring - Configuration C5-OPS-23 Managing Vulnerabilities, Malfunctions and Errors - System Hardening C5-PSS-11 Images for Virtual Machines and Containers 6.11.2 Security in development and support processes 6.9.1 Operational procedures and responsibilities 6.9.5 Control of operational software 6.9.6 Technical vulnerability management PR.IP-1 PR.IP-1: A baseline configuration of information technology/industrial control systems is created and maintained PR.IP-3 PR.IP-3: Configuration change control processes are in place PR.PT-2 PR.PT-2: Removable media is protected and its use restricted according to policy PR.PT-3 PR.PT-3: Access to systems and assets is controlled, incorporating the principle of least functionality PR.IP-1 PR.IP-1: A baseline configuration of information technology/industrial control systems is created and maintained incorporating security principles (e.g. concept of least functionality) PR.IP-3 PR.IP-3: Configuration change control processes are in place PR.PT-2 PR.PT-2: Removable media is protected and its use restricted according to policy PR.PT-3 PR.PT-3: The principle of least functionality is incorporated by configuring systems to provide only essential capabilities ISM-0912 Change and configuration management plan ISM-1409 Hardening operating systems ISM-1914 Approved operating system configurations BSI-23 Baseline configuration establishment BSI-24 Configuration change control BSI-26 System component inventory 8.1 User end point devices 8.24 Use of cryptography 8.9 Configuration management 8.1 User endpoint devices 8.20 Networks security 8.9 Configuration management SOC2-CC5.2 CC5.2 General controls over technology (COSO principle 11) SOC2-CC7.1 CC7.1 Detecting configuration changes and new vulnerabilities SOC2-CC8.1 CC8.1 Managing changes to procedures, software, data and infrastructure E8-MACRO-ML1 Configure Microsoft Office Macro Settings (ML1) E8-UAH-ML2 User Application Hardening - Maturity Level 2 API1164-14 Physical Security API1164-22 Configuration management for OT systems BMA-22 Patch Management BMA-9 Information Technology Services Management CA-ITSG33-SC-01 Security Control Catalogue ITSG33-CM Configuration Management (CM) FEDRAMP-CM-1 Configuration Management Policy FEDRAMP-CM-2 Baseline Configuration IEC62304-4.1 Quality Management System IEC62304-5.1 Software Development Planning IEC62443-14 System security hardening IEC62443-22 Configuration management for OT systems ISO27019-14 System security hardening ISO27019-22 Configuration management for OT systems NISTSP145-7 Cloud Procurement Standards Aligned to NIST SP 800-145 Definition NISTSP145-8 Governance, Reporting, and Stakeholder Education on Cloud Definition 3.14.4e Refresh Systems and Components from a Trusted Baseline 3.4.2e Automated Detection and Remediation of Unauthorized Software NISTSP82-1 OT Security Program Governance, Policy, Roles, and Safety-Security Integration NISTSP82-5 OT Configuration Management, Patching, Vulnerability Management, and Malware Protection CE-SC.1 Remove or Disable Unused Software CE-SC.2 Change Default Passwords on Devices and Software AS9100D-8.1 Operational Planning and Control AWWA-4.3 Configuration Management Clause 10 Change and configuration management AUCDR-IS-2 Secure the network and systems within the data environment AESCSF-ACM-2 Configuration management SUP.8 Configuration Management CA-SB327-1798.91.04a Reasonable Security Feature Requirement CRA-Art.13_AnnexI Manufacturer obligations and essential requirements (Article 13 + Annex I) CJIS-7 Configuration Management CAT-D3-3 Corrective controls FFIEC-10 Secure configuration standards ISO-26262-8-7 Configuration management ISO20000-10 Configuration management 27400-6.4 Default Configuration Security 7.5.2 Creating and updating documented information ITIL4-10 Configuration management Art.21.2.g Basic cyber hygiene practices and cybersecurity training NISTPF-8 Protect-P Information Protection Processes (PR.PO-P) NISTSP144-7 Cloud Workload Protection, Containers, Serverless, and Configuration NISTSP146-4 IaaS Operational Recommendations and Workload Hardening OSFIB13-3 Cyber Security: Identification, Protection, Detection, Response, Recovery OMANCS-5 Network, Endpoint, System Development, and Configuration Security OPENBANK-3 Mutual TLS, Token Binding, Request Signing (JWS), Key Management PCI-P2PE-10 Secure configuration standards PCI-PIN-10 Secure configuration standards PCI-SSF-10 Secure configuration standards PSDTWO-2 SCA Exemptions and Risk-Based Authentication CISABD-1 Take Ownership of Customer Security Outcomes ISMSP-SYS-01 System Hardening and Patch Management 3(d) Sec. 3(d) (now 3(b)) Provide agency configuration baselines for cloud services (FedRAMP) Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected .
Other controls in PR - Protect NIST-CSF-PR.AA-01 Identities and credentials for authorized users, services, and hardware are managed by the organization NIST-CSF-PR.AA-02 Identities are proofed and bound to credentials based on the context of interactions NIST-CSF-PR.AA-03 Users, services, and hardware are authenticated NIST-CSF-PR.AA-04 Identity assertions are protected, conveyed, and verified NIST-CSF-PR.AA-05 Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties NIST-CSF-PR.AA-06 Physical access to assets is managed, monitored, and enforced commensurate with risk NIST-CSF-PR.AT-01 Personnel are provided with awareness and training so that they possess the knowledge and skills to perform general tasks with cybersecurity risks in mind NIST-CSF-PR.AT-02 Individuals in specialized roles are provided with awareness and training so that they possess the knowledge and skills to perform relevant tasks with cybersecurity risks in mind You are reading one control. How much of NIST Cybersecurity Framework 2.0 have you already done? NIST Cybersecurity Framework 2.0 NIST-CSF-PR.PS-01 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of NIST Cybersecurity Framework 2.0 your existing evidence covers. Hold ISO 27001:2022 and 73 of 106 NIST Cybersecurity Framework 2.0 controls already carry evidence.
Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 174 were rejected on the ISO 27001:2022 pair alone.
Query this from an agent The graph holds this control, the 227 it maps to, and the evidence behind each claim, over MCP and REST.