NIST SP 800-53 Rev 5
CM - Configuration Management

NIST SP 800-53 Rev 5 NIST800-CM-2: CM-2 Baseline Configuration

a. Develop, document, and maintain under configuration control, a current baseline configuration of the system; and b. Review and update the baseline configuration of the system: 1. [Assignment: organization-defined frequency]; 2. When required due to [Assignment: organization-defined circumstances]; and 3. When system components are installed or upgraded.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 71 controls across 30 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

CIS Controls v8 · 10 controls

  • CIS-12.3 Securely Manage Network Infrastructure
  • CIS-16.7 Use Standard Hardening Configuration Templates for Application Infrastructure
  • CIS-16.8 Separate Production and Non-Production Systems
  • CIS-2.1 Establish and Maintain a Software Inventory
  • CIS-2.2 Ensure Authorized Software is Currently Supported
  • CIS-2.4 Utilize Automated Software Inventory Tools
  • CIS-4.1 Establish and Maintain a Secure Configuration Process
  • CIS-4.2 Establish and Maintain a Secure Configuration Process for Network Infrastructure
  • CIS-4.6 Securely Manage Enterprise Assets and Software
  • CIS-7.3 Perform Automated Operating System Patch Management

PCI DSS 4.0 · 8 controls

  • 1.2.1 1.2.1 Ruleset configuration standards for NSCs
  • 1.2.5 1.2.5 Allowed services, protocols and ports justified
  • 1.2.8 1.2.8 NSC configuration files secured and consistent
  • 12.6.1 12.6.1 Formal security awareness program
  • 2.2.1 2.2.1 System configuration standards maintained
  • 2.2.5 2.2.5 Insecure services, protocols or daemons secured
  • 6.5.6 6.5.6 Remove test data and accounts before production
  • 6.5.1 6.5.1 Change control procedure for production

FedRAMP High · 4 controls

  • CM-2 Baseline Configuration
  • CM-2(2) Automation Support for Accuracy and Currency
  • CM-2(3) Retention of Previous Configurations
  • CM-2(7) Configure Systems and Components for High-Risk Areas

FedRAMP Moderate · 4 controls

  • CM-2 Baseline Configuration
  • CM-2(2) Automation Support for Accuracy and Currency
  • CM-2(3) Retention of Previous Configurations
  • CM-2(7) Configure Systems and Components for High-Risk Areas
  • ASD37-10 Server application hardening (Very Good)
  • ASD37-11 Operating system hardening (Very Good)
  • ASD37-36 System recovery capabilities (Very Good)
  • ASBv3-PV-1 Define and establish secure configurations
  • ASBv3-PV-3 Define and establish secure configurations for compute resources
  • ASBv3-PV-4 Audit and enforce secure configurations for compute resources

C5 (Germany) · 3 controls

  • C5-COS-07 Documentation of the network topology
  • C5-DEV-08 Version Control
  • C5-OPS-23 Managing Vulnerabilities, Malfunctions and Errors - System Hardening

NIST SP 800-128 · 3 controls

SOC 2 · 3 controls

  • SOC2-CC5.2 CC5.2 General controls over technology (COSO principle 11)
  • SOC2-CC7.1 CC7.1 Detecting configuration changes and new vulnerabilities
  • SOC2-CC8.1 CC8.1 Managing changes to procedures, software, data and infrastructure
  • ANSSI-HYG-14 Apply a Minimum Security Level Across the Whole Estate
  • ANSSI-HYG-16 Use a Centralised Management Tool to Standardise Security Policies

CMMC 2.0 · 2 controls

ISO 27001:2022 · 2 controls

  • 8.31 Separation of development, test and production environments
  • 8.9 Configuration management

ISO 27002:2022 · 2 controls

  • 8.31 Separation of development, test and production environments
  • 8.9 Configuration management

NIST SP 800-172 · 2 controls

  • 3.14.4e Refresh Systems and Components from a Trusted Baseline
  • 3.4.1e Authoritative Source for Software and Firmware

NIST SP 800-218 · 2 controls

  • E8-UAH-ML2 User Application Hardening - Maturity Level 2
  • ZTMM-DEV-AO Devices Pillar: Automation and Orchestration
  • STIG-PGM-1 STIG/SRG applicability determination and baseline

NIST SP 800-160 · 1 control

  • CM-2 CM-2 Baseline Configuration
  • CM-2 CM-2 Baseline Configuration
  • CM-2 CM-2 Baseline Configuration

UK Cyber Essentials · 1 control

  • CE-SC.1 Remove or Disable Unused Software
  • 3(d) Sec. 3(d) (now 3(b)) Provide agency configuration baselines for cloud services (FedRAMP)

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in CM - Configuration Management

You are reading one control. How much of NIST SP 800-53 Rev 5 have you already done?

NIST SP 800-53 Rev 5 NIST800-CM-2 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of NIST SP 800-53 Rev 5 your existing evidence covers. Hold ISO 27001:2022 and 163 of 1014 NIST SP 800-53 Rev 5 controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 342 were rejected on the ISO 27001:2022 pair alone.

Query this from an agent

The graph holds this control, the 71 it maps to, and the evidence behind each claim, over MCP and REST.