# CM-02 Baseline Configuration

NIST SP 800-53 control. Family: CM Configuration Management. Function: preventative. Baselines: low, moderate, high. Mapping licence: CC BY-SA 4.0.

Statement: a. Develop, document, and maintain under configuration control, a current baseline configuration of the system; and b. Review and update the baseline configuration of the system: 1. [Assignment: organization-defined frequency]; 2. When required due to [Assignment: organization-defined circumstances]; and 3. When system components are installed or upgraded.
Guidance: Baseline configurations for systems and system components include connectivity, operational, and communications aspects of systems. Baseline configurations are documented, formally reviewed, and agreed-upon specifications for systems or configuration items within those systems. Baseline configurations serve as a basis for future builds, releases, or changes to systems and include security and privacy control implementations, operational procedures, information about system components, network topology, and logical placement of components in the system architecture. Maintaining baseline configurations requires creating new baselines as organizational systems change over time. Baseline configurations of systems reflect the current enterprise architecture.

## Enhancements (4)
- CM-02(02) Automation Support for Accuracy and Currency. Baselines: moderate, high
- CM-02(03) Retention of Previous Configurations. Baselines: moderate, high
- CM-02(06) Development and Test Environments
- CM-02(07) Configure Systems and Components for High-risk Areas. Baselines: moderate, high
Withdrawn by NIST: CM-02(01) (now in CM-02); CM-02(04) (now in CM-07(04)); CM-02(05) (now in CM-07(05)).
Each enhancement's statement: /api/v1/controls/CM-02?fields=enhancements

## Patterns that use it (23)
- Critical (11): SP-001 Client Module; SP-002 Server Module; SP-008 Public Web Server Pattern; SP-011 Cloud Computing Pattern; SP-015 Secure Remote Working; SP-023 Industrial Control Systems; SP-025 Advanced Monitoring and Detection; SP-026 PCI Full Environment; SP-028 Secure DevOps Pipeline Pattern; SP-045 AI Governance and Responsible AI; SP-049 AI in Security Operations (draft)
- Important (10): SP-012 Secure Software Development Lifecycle; SP-017 Secure Network Zone Module; SP-029 Zero Trust Architecture; SP-030 API Security; SP-036 Incident Response; SP-037 Privileged User Management; SP-038 Vulnerability Management and Patching; SP-046 External Attack Surface Management; SP-047 Secure Agentic AI Frameworks; SP-054 CBDC and Digital Currency Infrastructure (draft)
- Standard (2): SP-051 Tokenised Asset Security Architecture (draft); SP-053 Zero-Knowledge Proof Architecture (draft)

## Clauses by framework (77 frameworks)
- iso_27001_2022: A.8.9
- iso_27002_2022: 5.37, 8.9, 8.31
- cobit_2019: BAI10
- pci_dss_v4: 1.2, 1.2.1, 2.1, 2.2
- nist_csf_2: PR.PS-01
- cis_controls_v8: CIS 4, CIS 4.1, CIS 12, CIS 16.7
- soc2_tsc: CC6.1-POF7, CC6.7-POF1, CC7.1, CC7.1-POF1, CC8.1
- finos_ccc: CCC-C14
- iso_42001_2023: A.4.2, A.6.2.3
- iec_62443: 3-3 SR 7.6
- nis2: Art. 21(2)(g)
- mas_trm: 11
- bsi_grundschutz: NET.1.2, NET.3.1, SYS.1.1, SYS.2.1
- anssi: Hygiene.5, Hygiene.18, SecNumCloud.13.1
- osfi_b13: B-13.2.2
- finma_circular: IV.A(28), IV.A(29), IV.A(30), IV.A(31)
- gdpr: Art.25(1), Art.32(1)(b)
- dora: Art.7(1), Art.9(1)
- bio2: 5.37, 8.9, 8.31
- rbi_csf: Annex1.5
- fisc: FISC.O3, FISC.O13, FISC.T7, FISC.T14
- hkma_tme1: TME1.4.1, TME1.4.3
- mlps_2: 8.1.9.5, 8.1.10.4, 8.1.10.6
- dnb_good_practice: DNB.3.2, DNB.10.3, DNB.10.5, DNB.13.1, DNB.13.2
- cra: CRA.I.2b, CRA.Info.3
- swift_cscf: SWIFT.2.3
- cbb_tm: TM-5
- cbuae: CR-7
- nca_ecc: 2-3, 5-1
- qatar_nia: OS, SD
- sama_csf: 3.3, 3.5, 3.8, 4.3
- uae_ia: T7
- bog_cisd: CISD-VI
- bom_ctrm: 3.1, 3.2
- cbe_csf: CTO-7, CTO-12
- cbn_csf: Part3.3
- popia: s19
- sa_js2: JS2-7.2
- bcbs_239: Principle 2
- bot_cyber: Ch2.1
- cpmi_pfmi: CG.PR, PFMI.P17
- eba_ict: 3.4.4, 3.5(a)
- ecb_croe: CROE.2.3.4
- ffiec_is: II.C.2, II.C.10
- iosco_cyber: ID-4
- nydfs_500: 500.8
- sebi_cscrf: PR.IP
- cmmc_2: CM
- nerc_cip: CIP-010-4
- nrc_73_54: RG5.71-B-CM
- ieee_1686: 5.4
- ferc_cip: Order 887
- doe_c2m2: ASSET
- api_1164: Sec 7
- awia: AWWA Sec 2
- iaea_nss: Sec 5.4
- pci_pts: K
- fips_140: FIPS 140-3 §7.6
- pci_hsm: 8
- isae_3402: Clause 4, Clause 9
- fca_sysc_13: SYSC 13.7.1, SYSC 13.7.2
- fda_21_cfr_11: §11.10(f)
- fda_cyber: PU-2, SA-3
- hitrust_csf: 09.a
- iso_27799: 12.1
- lloyds_ms: MS8.4
- naic_ds: 4-config, 4B
- nhs_dspt: NDG-8.3
- pra_ss1_23: P3.3, P-IT.3
- solvency_ii: DR.266, EIOPA-ICT-4.8
- owasp_masvs_v2: MASVS-CODE-1, MASVS-CODE-2
- csa_ccm_v4: AIS-06, CCC-06, CCC-07, IVS-04, IVS-05, UEM-03, UEM-05, UEM-07
- csa_aicm: AIS-06, CCC-06, CCC-07, I&S-04, I&S-05, UEM-03, UEM-05, UEM-07
- mica: Art.62(5)
- basel_sco60: SCO60.14, SCO60.51, SCO60.65
- bssc: GSP-14, NOS-03
- sec_custody_digital: SEC-CD-08
OSA's mapping for iso_27001_2022 and nist_csf_2 takes NIST's published crosswalk as its base. A clause not marked as OSA's own is in that crosswalk.

## More
- This control as JSON, with guidance and ATT&CK techniques: /api/v1/controls/CM-02
- Clauses only: /api/v1/controls/CM-02?fields=mappings
- Page for people: /controls/cm-02/
- Found an error? Open an issue at https://github.com/opensecurityarchitecture/osa-data/issues with the id, what OSA says and what the source says.
