NIST SP 1800-32
NIST SP 1800-32: Systems Security

NIST SP 1800-32 NIST1800-32-14: System security hardening

System security hardening. Control from NIST SP 1800-32 framework, domain: NIST SP 1800-32: Systems Security.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 68 controls across 35 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

  • ASD37-04 User application hardening (Essential)
  • ASD37-10 Server application hardening (Very Good)
  • ASD37-11 Operating system hardening (Very Good)

BSI IT-Grundschutz · 3 controls

  • BSI-23 Baseline configuration establishment
  • BSI-24 Configuration change control
  • BSI-26 System component inventory

NIST SP 800-53 Rev 5 · 3 controls

API 1164 · 2 controls

  • API1164-14 Physical Security
  • API1164-22 Configuration management for OT systems

FedRAMP Rev 5 · 2 controls

  • FEDRAMP-CM-1 Configuration Management Policy
  • FEDRAMP-CM-2 Baseline Configuration
  • IEC62304-4.1 Quality Management System
  • IEC62304-5.1 Software Development Planning

IEC 62443 · 2 controls

  • IEC62443-14 System security hardening
  • IEC62443-22 Configuration management for OT systems

ISO/IEC 27019:2024 · 2 controls

  • ISO27019-14 System security hardening
  • ISO27019-22 Configuration management for OT systems

NIST SP 800-190 · 2 controls

  • NISTSP82-1 OT Security Program Governance, Policy, Roles, and Safety-Security Integration
  • NISTSP82-5 OT Configuration Management, Patching, Vulnerability Management, and Malware Protection
  • AS9100D-8.1 Operational Planning and Control
  • Clause 10 Change and configuration management
  • SUP.8 Configuration Management
  • CA-ITSG33-SC-01 Security Control Catalogue
  • CJIS-7 Configuration Management
  • CAT-D3-3 Corrective controls
  • FFIEC-10 Secure configuration standards
  • ISO-26262-8-7 Configuration management
  • ISO20000-10 Configuration management

ISO/IEC 27400:2022 · 1 control

  • 27400-6.4 Default Configuration Security

ITIL 4 · 1 control

  • ITIL4-10 Configuration management
  • NISTPF-8 Protect-P Information Protection Processes (PR.PO-P)

OSFI B-13 · 1 control

  • OSFIB13-3 Cyber Security: Identification, Protection, Detection, Response, Recovery
  • OMANCS-5 Network, Endpoint, System Development, and Configuration Security
  • OPENBANK-3 Mutual TLS, Token Binding, Request Signing (JWS), Key Management

PCI P2PE · 1 control

  • PCI-P2PE-10 Secure configuration standards

PCI PIN Security · 1 control

  • PCI-PIN-10 Secure configuration standards

PCI SSF · 1 control

  • PCI-SSF-10 Secure configuration standards

PSD2 SCA · 1 control

  • PSDTWO-2 SCA Exemptions and Risk-Based Authentication
  • CISABD-1 Take Ownership of Customer Security Outcomes

South Korea ISMS-P · 1 control

  • ISMSP-SYS-01 System Hardening and Patch Management

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in NIST SP 1800-32: Systems Security

Query this from an agent

The graph holds this control, the 68 it maps to, and the evidence behind each claim, over MCP and REST.