NIST Cybersecurity Framework 2.0
PR - Protect

NIST Cybersecurity Framework 2.0 NIST-CSF-PR.PS-01: Configuration management practices are established and applied

Configuration management practices are established and applied. Control from NIST Cybersecurity Framework 2.0 framework, domain: PR - Protect.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 227 controls across 77 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

PCI DSS 4.0 · 13 controls

  • 1.2.1 1.2.1 Ruleset configuration standards for NSCs
  • 1.2.5 1.2.5 Allowed services, protocols and ports justified
  • 1.2.6 1.2.6 Security features for insecure services in use
  • 1.2.7 1.2.7 Six-monthly review of NSC configurations
  • 1.2.8 1.2.8 NSC configuration files secured and consistent
  • 11.3.2 11.3.2 Quarterly ASV external vulnerability scans
  • 2.2.1 2.2.1 System configuration standards maintained
  • 2.2.2 2.2.2 Vendor default accounts managed
  • 2.2.4 2.2.4 Only necessary functionality enabled
  • 2.2.5 2.2.5 Insecure services, protocols or daemons secured
  • 2.2.6 2.2.6 System security parameters configured against misuse
  • 2.3.1 2.3.1 Wireless vendor defaults changed or confirmed secure
  • 6.5.1 6.5.1 Change control procedure for production

NIST SP 800-53 Rev 5 · 11 controls

  • AM-2 Use only approved services
  • ASBv3-GS-5 Define and implement security posture management strategy
  • ASBv3-NS-7 Simplify network security configuration
  • ASBv3-NS-8 Detect and disable insecure services and protocols
  • ASBv3-PA-6 Use privileged access workstations
  • ASBv3-PV-1 Define and establish secure configurations
  • ASBv3-PV-3 Define and establish secure configurations for compute resources
  • ASBv3-PV-4 Audit and enforce secure configurations for compute resources
  • PV-2 Audit and enforce secure configurations

CIS Controls v8 · 9 controls

  • CIS-12.3 Securely Manage Network Infrastructure
  • CIS-13.5 Manage Access Control for Remote Assets
  • CIS-16.7 Use Standard Hardening Configuration Templates for Application Infrastructure
  • CIS-18.1 Establish and Maintain a Penetration Testing Program
  • CIS-4.1 Establish and Maintain a Secure Configuration Process
  • CIS-4.2 Establish and Maintain a Secure Configuration Process for Network Infrastructure
  • CIS-4.6 Securely Manage Enterprise Assets and Software
  • CIS-4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
  • CIS-7.3 Perform Automated Operating System Patch Management

CMMC 2.0 · 8 controls

FedRAMP High · 8 controls

  • CM-2 Baseline Configuration
  • CM-3 Configuration Change Control
  • CM-5 Access Restrictions for Change
  • CM-6 Configuration Settings
  • CM-6(1) Automated Management, Application, and Verification
  • CM-7 Least Functionality
  • CM-7(1) Periodic Review
  • CM-9 Configuration Management Plan

FedRAMP Moderate · 8 controls

  • CM-2 Baseline Configuration
  • CM-3 Configuration Change Control
  • CM-5 Access Restrictions for Change
  • CM-6 Configuration Settings
  • CM-6(1) Automated Management, Application, and Verification
  • CM-7 Least Functionality
  • CM-7(1) Periodic Review
  • CM-9 Configuration Management Plan

NIST SP 800-218 · 7 controls

  • ASD37-01 Application control (Essential)
  • ASD37-03 Configure Microsoft Office macro settings (Essential)
  • ASD37-04 User application hardening (Essential)
  • ASD37-09 OS generic exploit mitigation (Excellent)
  • ASD37-10 Server application hardening (Very Good)
  • ASD37-11 Operating system hardening (Very Good)
  • ANSSI-HYG-12 Change Default Authentication Elements on Equipment and Services
  • ANSSI-HYG-14 Apply a Minimum Security Level Across the Whole Estate
  • ANSSI-HYG-16 Use a Centralised Management Tool to Standardise Security Policies
  • ANSSI-HYG-17 Enable and Configure the Local Firewall on Workstations
  • ANSSI-HYG-33 Adopt Security Policies Dedicated to Mobile Terminals

C5 (Germany) · 4 controls

  • C5-DEV-03 Policies for changes to information systems
  • C5-OPS-16 Logging and Monitoring - Configuration
  • C5-OPS-23 Managing Vulnerabilities, Malfunctions and Errors - System Hardening
  • C5-PSS-11 Images for Virtual Machines and Containers

ISO 27701:2019 · 4 controls

  • 6.11.2 Security in development and support processes
  • 6.9.1 Operational procedures and responsibilities
  • 6.9.5 Control of operational software
  • 6.9.6 Technical vulnerability management
  • PR.IP-1 PR.IP-1: A baseline configuration of information technology/industrial control systems is created and maintained
  • PR.IP-3 PR.IP-3: Configuration change control processes are in place
  • PR.PT-2 PR.PT-2: Removable media is protected and its use restricted according to policy
  • PR.PT-3 PR.PT-3: Access to systems and assets is controlled, incorporating the principle of least functionality
  • PR.IP-1 PR.IP-1: A baseline configuration of information technology/industrial control systems is created and maintained incorporating security principles (e.g. concept of least functionality)
  • PR.IP-3 PR.IP-3: Configuration change control processes are in place
  • PR.PT-2 PR.PT-2: Removable media is protected and its use restricted according to policy
  • PR.PT-3 PR.PT-3: The principle of least functionality is incorporated by configuring systems to provide only essential capabilities

NIST SP 800-161 Rev 1 · 4 controls

NIST SP 800-171 Rev 3 · 4 controls

  • ISM-0912 Change and configuration management plan
  • ISM-1409 Hardening operating systems
  • ISM-1914 Approved operating system configurations

BSI IT-Grundschutz · 3 controls

  • BSI-23 Baseline configuration establishment
  • BSI-24 Configuration change control
  • BSI-26 System component inventory

ISO 27001:2022 · 3 controls

  • 8.1 User end point devices
  • 8.24 Use of cryptography
  • 8.9 Configuration management

ISO 27002:2022 · 3 controls

  • 8.1 User endpoint devices
  • 8.20 Networks security
  • 8.9 Configuration management

SOC 2 · 3 controls

  • SOC2-CC5.2 CC5.2 General controls over technology (COSO principle 11)
  • SOC2-CC7.1 CC7.1 Detecting configuration changes and new vulnerabilities
  • SOC2-CC8.1 CC8.1 Managing changes to procedures, software, data and infrastructure

ACSC Essential Eight · 2 controls

  • E8-MACRO-ML1 Configure Microsoft Office Macro Settings (ML1)
  • E8-UAH-ML2 User Application Hardening - Maturity Level 2

API 1164 · 2 controls

  • API1164-14 Physical Security
  • API1164-22 Configuration management for OT systems
  • BMA-22 Patch Management
  • BMA-9 Information Technology Services Management
  • CA-ITSG33-SC-01 Security Control Catalogue
  • ITSG33-CM Configuration Management (CM)

FedRAMP Rev 5 · 2 controls

  • FEDRAMP-CM-1 Configuration Management Policy
  • FEDRAMP-CM-2 Baseline Configuration
  • IEC62304-4.1 Quality Management System
  • IEC62304-5.1 Software Development Planning

IEC 62443 · 2 controls

  • IEC62443-14 System security hardening
  • IEC62443-22 Configuration management for OT systems

ISO/IEC 27019:2024 · 2 controls

  • ISO27019-14 System security hardening
  • ISO27019-22 Configuration management for OT systems

NIST SP 1800-32 · 2 controls

NIST SP 800-145 · 2 controls

  • NISTSP145-7 Cloud Procurement Standards Aligned to NIST SP 800-145 Definition
  • NISTSP145-8 Governance, Reporting, and Stakeholder Education on Cloud Definition

NIST SP 800-172 · 2 controls

  • 3.14.4e Refresh Systems and Components from a Trusted Baseline
  • 3.4.2e Automated Detection and Remediation of Unauthorized Software

NIST SP 800-190 · 2 controls

  • NISTSP82-1 OT Security Program Governance, Policy, Roles, and Safety-Security Integration
  • NISTSP82-5 OT Configuration Management, Patching, Vulnerability Management, and Malware Protection

UK Cyber Essentials · 2 controls

  • CE-SC.1 Remove or Disable Unused Software
  • CE-SC.2 Change Default Passwords on Devices and Software
  • AS9100D-8.1 Operational Planning and Control
  • Clause 10 Change and configuration management
  • AUCDR-IS-2 Secure the network and systems within the data environment
  • AESCSF-ACM-2 Configuration management
  • SUP.8 Configuration Management
  • CA-SB327-1798.91.04a Reasonable Security Feature Requirement

DORA · 1 control

  • CRA-Art.13_AnnexI Manufacturer obligations and essential requirements (Article 13 + Annex I)
  • CJIS-7 Configuration Management
  • CAT-D3-3 Corrective controls
  • FFIEC-10 Secure configuration standards

HIPAA Security Rule · 1 control

  • ISO-26262-8-7 Configuration management
  • ISO20000-10 Configuration management

ISO/IEC 27400:2022 · 1 control

  • 27400-6.4 Default Configuration Security

ISO/IEC 42001:2023 · 1 control

  • 7.5.2 Creating and updating documented information

ITIL 4 · 1 control

  • ITIL4-10 Configuration management

NIS2 Directive · 1 control

  • Art.21.2.g Basic cyber hygiene practices and cybersecurity training
  • NISTPF-8 Protect-P Information Protection Processes (PR.PO-P)

NIST SP 800-144 · 1 control

  • NISTSP144-7 Cloud Workload Protection, Containers, Serverless, and Configuration

NIST SP 800-146 · 1 control

  • NISTSP146-4 IaaS Operational Recommendations and Workload Hardening

OSFI B-13 · 1 control

  • OSFIB13-3 Cyber Security: Identification, Protection, Detection, Response, Recovery
  • OMANCS-5 Network, Endpoint, System Development, and Configuration Security
  • OPENBANK-3 Mutual TLS, Token Binding, Request Signing (JWS), Key Management

PCI P2PE · 1 control

  • PCI-P2PE-10 Secure configuration standards

PCI PIN Security · 1 control

  • PCI-PIN-10 Secure configuration standards

PCI SSF · 1 control

  • PCI-SSF-10 Secure configuration standards

PSD2 SCA · 1 control

  • PSDTWO-2 SCA Exemptions and Risk-Based Authentication
  • CISABD-1 Take Ownership of Customer Security Outcomes

South Korea ISMS-P · 1 control

  • ISMSP-SYS-01 System Hardening and Patch Management
  • 3(d) Sec. 3(d) (now 3(b)) Provide agency configuration baselines for cloud services (FedRAMP)

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in PR - Protect

You are reading one control. How much of NIST Cybersecurity Framework 2.0 have you already done?

NIST Cybersecurity Framework 2.0 NIST-CSF-PR.PS-01 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of NIST Cybersecurity Framework 2.0 your existing evidence covers. Hold ISO 27001:2022 and 73 of 106 NIST Cybersecurity Framework 2.0 controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 174 were rejected on the ISO 27001:2022 pair alone.

Query this from an agent

The graph holds this control, the 227 it maps to, and the evidence behind each claim, over MCP and REST.