NIST SP 800-53 Rev 5
CM - Configuration Management

NIST SP 800-53 Rev 5 NIST800-CM-6: CM-6 Configuration Settings

a. Establish and document configuration settings for components employed within the system that reflect the most restrictive mode consistent with operational requirements using [Assignment: organization-defined common secure configurations]; b. Implement the configuration settings; c. Identify, document, and approve any deviations from established configuration settings for [Assignment: organization-defined system components] based on [Assignment: organization-defined operational requirements]; and d. Monitor and control changes to the configuration settings in accordance with organizational policies and procedures.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 100 controls across 38 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

CIS Controls v8 · 8 controls

  • CIS-10.3 Disable Autorun and Autoplay for Removable Media
  • CIS-16.7 Use Standard Hardening Configuration Templates for Application Infrastructure
  • CIS-4.1 Establish and Maintain a Secure Configuration Process
  • CIS-4.2 Establish and Maintain a Secure Configuration Process for Network Infrastructure
  • CIS-4.6 Securely Manage Enterprise Assets and Software
  • CIS-4.7 Manage Default Accounts on Enterprise Assets and Software
  • CIS-4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
  • CIS-4.9 Configure Trusted DNS Servers on Enterprise Assets
  • ASBv3-DP-8 Ensure security of key and certificate repository
  • ASBv3-DS-3 Secure DevOps infrastructure
  • ASBv3-NS-7 Simplify network security configuration
  • ASBv3-PV-1 Define and establish secure configurations
  • ASBv3-PV-4 Audit and enforce secure configurations for compute resources
  • PV-2 Audit and enforce secure configurations

NIST SP 800-128 · 5 controls

NIST SP 800-218 · 5 controls

PCI DSS 4.0 · 5 controls

  • 1.2.1 1.2.1 Ruleset configuration standards for NSCs
  • 1.2.7 1.2.7 Six-monthly review of NSC configurations
  • 1.2.8 1.2.8 NSC configuration files secured and consistent
  • 2.2.1 2.2.1 System configuration standards maintained
  • 2.2.6 2.2.6 System security parameters configured against misuse

ACSC Essential Eight · 4 controls

  • E8-MACRO-ML1 Configure Microsoft Office Macro Settings (ML1)
  • E8-UAH-ML1 User Application Hardening - Maturity Level 1
  • E8-UAH-ML2 User Application Hardening - Maturity Level 2
  • E8-UAH-ML3 User Application Hardening - Maturity Level 3
  • ASD37-03 Configure Microsoft Office macro settings (Essential)
  • ASD37-04 User application hardening (Essential)
  • ASD37-10 Server application hardening (Very Good)
  • ASD37-11 Operating system hardening (Very Good)

CMMC 2.0 · 4 controls

UK Cyber Essentials · 4 controls

  • CE-SC.1 Remove or Disable Unused Software
  • CE-SC.2 Change Default Passwords on Devices and Software
  • CE-SC.3 Disable Auto-Run Features
  • CE-SC.4 Authenticate Users Before Access
  • ANSSI-HYG-12 Change Default Authentication Elements on Equipment and Services
  • ANSSI-HYG-14 Apply a Minimum Security Level Across the Whole Estate
  • ANSSI-HYG-16 Use a Centralised Management Tool to Standardise Security Policies

SOC 2 · 3 controls

  • SOC2-CC5.2 CC5.2 General controls over technology (COSO principle 11)
  • SOC2-CC7.1 CC7.1 Detecting configuration changes and new vulnerabilities
  • SOC2-CC8.1 CC8.1 Managing changes to procedures, software, data and infrastructure

C5 (Germany) · 2 controls

  • C5-AM-02 Acceptable Use and Safe Handling of Assets Policy
  • C5-OPS-23 Managing Vulnerabilities, Malfunctions and Errors - System Hardening
  • STIG-GOV-CCI CCI and NIST SP 800-53 traceability
  • STIG-SRG-OS Operating system STIG hardening

FedRAMP High · 2 controls

  • CM-6 Configuration Settings
  • CM-6(1) Automated Management, Application, and Verification

FedRAMP Moderate · 2 controls

  • CM-6 Configuration Settings
  • CM-6(1) Automated Management, Application, and Verification

ISO 27001:2022 · 2 controls

  • 8.8 Management of technical vulnerabilities
  • 8.9 Configuration management

ISO 27002:2022 · 2 controls

  • 8.8 Management of technical vulnerabilities
  • 8.9 Configuration management

NIST SP 800-187 · 2 controls

API 1164 · 1 control

  • API1164-08 Configuration Management
  • AUCDR-IS-2 Secure the network and systems within the data environment
  • AESCSF-ACM-2 Configuration management

DORA · 1 control

NIS2 Directive · 1 control

  • Art.21.2.g Basic cyber hygiene practices and cybersecurity training

NIST SP 800-172 · 1 control

  • 3.4.2e Automated Detection and Remediation of Unauthorized Software
  • CM-6 CM-6 Configuration Settings
  • CM-6 CM-6 Configuration Settings
  • CM-6 CM-6 Configuration Settings
  • 3(d) Sec. 3(d) (now 3(b)) Provide agency configuration baselines for cloud services (FedRAMP)

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in CM - Configuration Management

You are reading one control. How much of NIST SP 800-53 Rev 5 have you already done?

NIST SP 800-53 Rev 5 NIST800-CM-6 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of NIST SP 800-53 Rev 5 your existing evidence covers. Hold ISO 27001:2022 and 163 of 1014 NIST SP 800-53 Rev 5 controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 342 were rejected on the ISO 27001:2022 pair alone.

Query this from an agent

The graph holds this control, the 100 it maps to, and the evidence behind each claim, over MCP and REST.