Frameworks / NIST SP 1800-32 / NIST1800-32-22 NIST SP 1800-32
NIST SP 1800-32: Supply Chain & Configuration
NIST SP 1800-32 NIST1800-32-22: Configuration management for OT systems Configuration management for OT systems. Control from NIST SP 1800-32 framework, domain: NIST SP 1800-32: Supply Chain & Configuration.
Maintained by Gerard Blokdyk · Verified against the published standard 31 May 2026 · Control text last updated 21 May 2026 What else in your programme already covers this This control maps to 69 controls across 36 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
ASD37-04 User application hardening (Essential) ASD37-10 Server application hardening (Very Good) ASD37-11 Operating system hardening (Very Good) BSI-23 Baseline configuration establishment BSI-24 Configuration change control BSI-26 System component inventory API1164-14 Physical Security API1164-22 Configuration management for OT systems FEDRAMP-CM-1 Configuration Management Policy FEDRAMP-CM-2 Baseline Configuration IEC62304-4.1 Quality Management System IEC62304-5.1 Software Development Planning IEC62443-14 System security hardening IEC62443-22 Configuration management for OT systems ISO27019-14 System security hardening ISO27019-22 Configuration management for OT systems NISTSP82-1 OT Security Program Governance, Policy, Roles, and Safety-Security Integration NISTSP82-5 OT Configuration Management, Patching, Vulnerability Management, and Malware Protection AS9100D-8.1 Operational Planning and Control AWWA-4.3 Configuration Management Clause 10 Change and configuration management SUP.8 Configuration Management CA-ITSG33-SC-01 Security Control Catalogue CJIS-7 Configuration Management CAT-D3-3 Corrective controls FFIEC-10 Secure configuration standards ISO-26262-8-7 Configuration management 8.9 Configuration management ISO20000-10 Configuration management 27400-6.4 Default Configuration Security ITIL4-10 Configuration management NISTPF-8 Protect-P Information Protection Processes (PR.PO-P) OSFIB13-3 Cyber Security: Identification, Protection, Detection, Response, Recovery OMANCS-5 Network, Endpoint, System Development, and Configuration Security OPENBANK-3 Mutual TLS, Token Binding, Request Signing (JWS), Key Management PCI-P2PE-10 Secure configuration standards PCI-PIN-10 Secure configuration standards PCI-SSF-10 Secure configuration standards PSDTWO-2 SCA Exemptions and Risk-Based Authentication CISABD-1 Take Ownership of Customer Security Outcomes ISMSP-SYS-01 System Hardening and Patch Management Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected .
Other controls in NIST SP 1800-32: Supply Chain & Configuration Query this from an agent The graph holds this control, the 69 it maps to, and the evidence behind each claim, over MCP and REST.