NIST SP 800-53 Revision 5.1 HIGH
CM Configuration Management

NIST SP 800-53 Revision 5.1 HIGH CM-2(3): Retention of Previous Configurations

Retain FedRAMP-defined number of previous baseline configurations (3) to support rollback.

What else in your programme already covers this

This control maps to 19 controls across 11 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

NIST SP 800-53 Rev 5 · 4 controls

PCI DSS 4.0 · 4 controls

  • 1.2.8 Configuration files secured and synchronised
  • 10.3.4 File integrity or change detection on logs
  • 11.5.2 Change detection mechanism (FIM)
  • 6.5.1 Changes to all system components in the production environment are made according to established procedures that include: • Reason for, and description of, the change. • Documentation of security impact. • Documented change approval

CIS Controls v8 · 2 controls

  • CIS-11.2 Perform Automated Backups
  • CIS-11.4 Establish and Maintain an Isolated Instance of Recovery Data

ISO 27002:2022 · 2 controls

  • 8.32 Change management
  • 8.9 Configuration management
  • ASD37-36 System recovery capabilities (Very Good)
  • SEC01-BP06 Automate deployment of standard security controls

C5 (Germany) · 1 control

NIST SP 800-172 · 1 control

  • 3.14.4e Refresh Systems and Components from a Trusted Baseline

NIST SP 800-218 · 1 control

SOC 2 · 1 control

  • SOC2-CC8.1 Change management processes are in place

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in CM Configuration Management

Query this from an agent

The graph holds this control, the 19 it maps to, and the evidence behind each claim, over MCP and REST.