Back to Frameworks

NIST SP 800-128

United States
v2011
10 domains
39 controls

Guide for Security-Focused Configuration Management

Verified

Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.

Framework Domains (10)

Controlling Configuration Changes

6 controls
Controls in the Controlling Configuration Changes domain of NIST SP 800-1286 controls
CodeTitle
SecCM-CHANGE-1Configuration Change Control Process
SecCM-CHANGE-3Access Restrictions for Change
SecCM-CHANGE-4Testing and Validation
SecCM-CHANGE-5Retention of Configuration Records
SecCM-CHANGE-6Automated Change Control Tools
SecCM-CHANGE-7Emergency Change Handling

Identifying & Implementing Configurations

5 controls
Controls in the Identifying & Implementing Configurations domain of NIST SP 800-1285 controls
CodeTitle
SecCM-ID-1Configuration Item Identification
SecCM-ID-2Baseline Configuration Development
SecCM-ID-3Common Secure Configurations
SecCM-ID-4Least Functionality
SecCM-ID-5Implementation and Provisioning

Monitoring

8 controls
Controls in the Monitoring domain of NIST SP 800-1288 controls
CodeTitle
SecCM-MONITOR-1Continuous Monitoring of Configurations
SecCM-MONITOR-2Configuration Drift Detection
SecCM-MONITOR-3Vulnerability Identification and Remediation
SecCM-MONITOR-4Compliance Reporting
SecCM-MONITOR-5Unauthorized Change Detection
SecCM-MONITOR-6Metrics and Measurement
SecCM-MONITOR-7Feedback into Baselines
SecCM-MONITOR-8Audit and Independent Assessment

NIST SP 800-128: Access Control

5 controls

Logical and physical access controls (NIST SP 800-128)

Controls in the NIST SP 800-128: Access Control domain of NIST SP 800-1285 controls
CodeTitle
SP800-128-ACCESS-RESTRICTAccess Restrictions for Change
SP800-128-BASELINEBaseline Configuration
SP800-128-CHANGE-CONTROLConfiguration Change Control
SP800-128-MONITORINGConfiguration Monitoring
SP800-128-SIASecurity Impact Analysis

NIST SP 800-128: Asset Management

5 controls

Information asset management (NIST SP 800-128)

Controls in the NIST SP 800-128: Asset Management domain of NIST SP 800-1285 controls
CodeTitle
SP800-128-CCBConfiguration Control Board
SP800-128-CONFIG-ITEMSConfiguration Items
SP800-128-INVENTORYComponent Inventory
SP800-128-PLAN-DOCConfiguration Management Plan
SP800-128-SECURE-CONFIGSecure Configurations of Information Systems

NIST SP 800-128: Communications Security

0 controls

Network and communications security (NIST SP 800-128)

NIST SP 800-128: Cryptography

0 controls

Cryptographic controls (NIST SP 800-128)

NIST SP 800-128: Information Security Policies

5 controls

Organizational information security policies (NIST SP 800-128)

Controls in the NIST SP 800-128: Information Security Policies domain of NIST SP 800-1285 controls
CodeTitle
SP800-128-PH-CONTROLSecCM Phase: Controlling Configuration Changes
SP800-128-PH-IDENTIFYSecCM Phase: Identifying and Implementing Configurations
SP800-128-PH-MONITORSecCM Phase: Monitoring
SP800-128-PH-PLANSecCM Phase: Planning
SP800-128-POLICYConfiguration Management Policy and Procedures

NIST SP 800-128: Operations Security

0 controls

Secure operations and monitoring (NIST SP 800-128)

Planning

5 controls
Controls in the Planning domain of NIST SP 800-1285 controls
CodeTitle
SecCM-PLAN-1SecCM Policy and Procedures
SecCM-PLAN-2SecCM Plan
SecCM-PLAN-3Roles and Responsibilities
SecCM-PLAN-4Integration with Organizational CM
SecCM-PLAN-5Tools, Techniques, and Resources

Maps to 1 other framework

39 total controls
NIST SP 800-53 Rev 5
21 source controls mapped|9 target controls covered
54%

Frequently Asked Questions

What is NIST SP 800-128?

NIST SP 800-128 is a compliance framework from United States with 10 domains and 39 controls. Guide for Security-Focused Configuration Management It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.

How many controls does NIST SP 800-128 have?

NIST SP 800-128 has 39 controls organised across 10 domains. The largest domains are Monitoring (8 controls), Controlling Configuration Changes (6 controls), Identifying & Implementing Configurations (5 controls). Each control defines specific requirements that organisations must implement to achieve compliance.

What frameworks does NIST SP 800-128 map to?

NIST SP 800-128 maps to 1 other compliance frameworks. The top mapping partners are NIST SP 800-53 Rev 5 (54% coverage). Use our comparison tool to explore control-level mappings between frameworks.

How do I get started with NIST SP 800-128 compliance?

Start your NIST SP 800-128 compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about NIST SP 800-128 requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 39 controls and track your progress.

Start Your Compliance Journey

Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 700 frameworks.

Get Started Free →

Free forever — no credit card required