NIST SP 800-123
Installation and Configuration

NIST SP 800-123 NISTSP123-2: Secure Server Installation and Configuration

Apply Section 3 secure installation including: server selection per organizational requirements + OS hardening per CIS Benchmarks + DISA STIGs + NSA SecGuide + vendor security guides (Microsoft + Red Hat + SUSE + Ubuntu + macOS) + remove unnecessary services + features + components + install only required software + apply security patches + enable secure default settings + disable default accounts + change default passwords. Configure per Section 4 secure baselines including: enable secure boot + UEFI + TPM 2.0 + disk encryption (BitLocker + LUKS + FileVault) + secure SSH/RDP + restrict remote management + audit log configuration + firewall enabled + IDS/IPS enabled where applicable.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

Query this from an agent

The graph holds this control, the 7 it maps to, and the evidence behind each claim, over MCP and REST.