← Controls / CM

CM-06 Configuration Settings

Configuration Management

Low Moderate High

Description

a. Establish and document configuration settings for components employed within the system that reflect the most restrictive mode consistent with operational requirements using [Assignment: organization-defined common secure configurations]; b. Implement the configuration settings; c. Identify, document, and approve any deviations from established configuration settings for [Assignment: organization-defined system components] based on [Assignment: organization-defined operational requirements]; and d. Monitor and control changes to the configuration settings in accordance with organizational policies and procedures.

Supplemental Guidance

Configuration settings are the parameters that can be changed in the hardware, software, or firmware components of the system that affect the security and privacy posture or functionality of the system. Information technology products for which configuration settings can be defined include mainframe computers, servers, workstations, operating systems, mobile devices, input/output devices, protocols, and applications. Parameters that impact the security posture of systems include registry settings; account, file, or directory permission settings; and settings for functions, protocols, ports, services, and remote connections. Privacy parameters are parameters impacting the privacy posture of systems, including the parameters required to satisfy other privacy controls. Privacy parameters include settings for access controls, data processing preferences, and processing and retention permissions. Organizations establish organization-wide configuration settings and subsequently derive specific configuration settings for systems. The established settings become part of the configuration baseline for the system. Common secure configurations (also known as security configuration checklists, lockdown and hardening guides, and security reference guides) provide recognized, standardized, and established benchmarks that stipulate secure configuration settings for information technology products and platforms as well as instructions for configuring those products or platforms to meet operational requirements. Common secure configurations can be developed by a variety of organizations, including information technology product developers, manufacturers, vendors, federal agencies, consortia, academia, industry, and other organizations in the public and private sectors. Implementation of a common secure configuration may be mandated at the organization level, mission and business process level, system level, or at a higher level, including by a regulatory agency. Common secure configurations include the United States Government Configuration Baseline [USGCB] and security technical implementation guides (STIGs), which affect the implementation of CM-6 and other controls such as AC-19 and CM-7. The Security Content Automation Protocol (SCAP) and the defined standards within the protocol provide an effective method to uniquely identify, track, and control configuration settings.

Changes from Rev 4

Minor text changes Changed parameter from specific information system checklists to specific common secure configurations Discussion adds explanation of privacy parameters

Enhancements (2)

What NIST adds to this control. Select one to read its statement.

CM-06(01) Automated Management, Application, and Verification High

Manage, apply, and verify configuration settings for [Assignment: organization-defined system components] using [Assignment: organization-defined automated mechanisms].

CM-06(02) Respond to Unauthorized Changes High

Take the following actions in response to unauthorized changes to [Assignment: organization-defined configuration settings]: [Assignment: organization-defined actions].

Withdrawn by NIST:

  • CM-06(03) Unauthorized Change Detection, now in SI-07
  • CM-06(04) Conformance Demonstration, now in CM-04

MITRE ATT&CK Techniques (344)

ATT&CK v16.1

Techniques mitigated by this control, mapped via CTID.

Reconnaissance 4 Initial Access 14 Execution 31 Persistence 85 Privilege Escalation 65 Defense Evasion 115 Credential Access 47 Discovery 9 Lateral Movement 19 Collection 19 Command & Control 33 Exfiltration 12 Impact 15
Show all 344 techniques grouped by tactic

Execution

Persistence

T1037 T1053 T1078 T1098 T1133 T1136 T1137 T1176 T1197 T1205 T1505 T1525 T1542 T1543 T1546 T1554 T1556 T1574 T1037.002 T1037.003 T1037.004 T1037.005 T1053.002 T1053.005 T1053.006 T1078.002 T1078.003 T1078.004 T1098.001 T1098.002 T1098.003 T1098.004 T1098.005 T1098.007 T1136.001 T1136.002 T1136.003 T1137.001 T1137.002 T1137.003 T1137.004 T1137.005 T1137.006 T1205.001 T1505.001 T1505.002 T1505.003 T1505.004 T1505.005 T1542.001 T1542.003 T1542.004 T1542.005 T1543.002 T1546.002 T1546.003 T1546.004 T1546.006 T1546.008 T1546.013 T1546.014 T1546.016 T1547.002 T1547.003 T1547.005 T1547.006 T1547.007 T1547.008 T1547.009 T1547.013 T1556.001 T1556.002 T1556.003 T1556.004 T1556.008 T1556.009 T1574.001 T1574.004 T1574.005 T1574.006 T1574.007 T1574.008 T1574.009 T1574.010 T1574.014

Privilege Escalation

T1037 T1053 T1055 T1068 T1078 T1098 T1134 T1484 T1543 T1546 T1548 T1574 T1611 T1037.002 T1037.003 T1037.004 T1037.005 T1053.002 T1053.005 T1053.006 T1055.008 T1078.002 T1078.003 T1078.004 T1098.001 T1098.002 T1098.003 T1098.004 T1098.005 T1098.007 T1134.001 T1134.002 T1134.003 T1134.005 T1543.002 T1546.002 T1546.003 T1546.004 T1546.006 T1546.008 T1546.013 T1546.014 T1546.016 T1547.002 T1547.003 T1547.005 T1547.006 T1547.007 T1547.008 T1547.009 T1547.013 T1548.001 T1548.002 T1548.003 T1548.004 T1548.006 T1574.001 T1574.004 T1574.005 T1574.006 T1574.007 T1574.008 T1574.009 T1574.010 T1574.014

Defense Evasion

T1027 T1036 T1055 T1070 T1078 T1127 T1134 T1197 T1205 T1211 T1216 T1218 T1220 T1221 T1222 T1484 T1542 T1548 T1550 T1553 T1556 T1562 T1574 T1599 T1601 T1610 T1612 T1622 T1647 T1027.010 T1036.001 T1036.003 T1036.005 T1036.007 T1036.010 T1055.008 T1070.001 T1070.002 T1070.003 T1070.007 T1070.008 T1070.009 T1078.002 T1078.003 T1078.004 T1127.001 T1127.002 T1134.001 T1134.002 T1134.003 T1134.005 T1205.001 T1216.001 T1216.002 T1218.001 T1218.002 T1218.003 T1218.004 T1218.005 T1218.007 T1218.008 T1218.009 T1218.012 T1218.013 T1218.014 T1218.015 T1222.001 T1222.002 T1542.001 T1542.003 T1542.004 T1542.005 T1548.001 T1548.002 T1548.003 T1548.004 T1548.006 T1550.001 T1550.002 T1550.003 T1553.001 T1553.003 T1553.004 T1553.005 T1556.001 T1556.002 T1556.003 T1556.004 T1556.008 T1556.009 T1562.001 T1562.002 T1562.003 T1562.004 T1562.006 T1562.009 T1562.010 T1562.011 T1562.012 T1564.002 T1564.006 T1564.007 T1564.009 T1574.001 T1574.004 T1574.005 T1574.006 T1574.007 T1574.008 T1574.009 T1574.010 T1574.014 T1599.001 T1601.001 T1601.002

Credential Access

Command & Control

Compliance Mappings

ISO 27001:2022

A.8.9

ISO 27002:2022

5.378.9

COBIT 2019

BAI10

CIS Controls v8

CIS 4CIS 4.1CIS 4.2CIS 4.6CIS 4.7CIS 10.5CIS 12CIS 12.1CIS 12.3CIS 16.7

NIST CSF 2.0

DE.CM-09PR.PS-01

SOC 2 TSC

CC6.1-POF7CC6.7-POF1CC7.1CC7.1-POF1CC8.1

PCI DSS v4.0.1

1.21.2.11.2.82.12.22.2.12.2.2

CSA CCM v4

CCC-06IVS-04UEM-05UEM-07

CSA AICM v1

CCC-06I&S-04UEM-05UEM-07

FINOS CCC

CCC-C14

ISO 42001:2023

A.4.2A.6.2.3

IEC 62443

3-3 SR 7.6

NIS2 Directive

Art. 21(2)(g)

MAS TRM

11

ASD Essential Eight

E8-3E8-3 ML1E8-3 ML3E8-4E8-4 ML1E8-4 ML2E8-4 ML3

BSI IT-Grundschutz

APP.1.1NET.1.2NET.3.1SYS.1.1SYS.2.1

ANSSI

Hygiene.18Hygiene.20SecNumCloud.13.1

FINMA Circular 2023/1

IV.A(28)IV.A(29)IV.C(64)

OSFI B-13

B-13.2.2B-13.3.2

EU GDPR

Art.25(1)Art.25(2)Art.32(1)(b)

EU DORA

Art.7(1)Art.9(1)

BIO2

5.378.9

RBI CSF

Annex1.5

FISC Security Guidelines

FISC.O3FISC.T7FISC.T14

LGPD + BCB 4893

LGPD.Art.46

HKMA TM-E-1

TME1.4.1

MLPS 2.0

8.1.5.38.1.10.48.1.10.6

DNB Good Practice

DNB.3.2DNB.13.1DNB.19.2DNB.20.1

EU CRA

CRA.I.2bCRA.Info.8a

SWIFT CSCF

SWIFT.1.3SWIFT.2.3SWIFT.2.10

SAMA CSF

3.33.53.84.3

NCA ECC

2-32-105-1

UAE IA

T7

CBB TM

TM-5

Qatar NIA

OS

CBUAE

CR-7

CBE CSF

CTO-6CTO-7CTO-12

SA JS2

JS2-7.2JS2-8.4

CBN CSF

Part3.3

BoG CISD

CISD-VI

POPIA

s19

BoM CTRM

3.13.2

IOSCO Cyber Resilience

PROT-6

CPMI-IOSCO PFMI

CG.PRPFMI.P17PFMI.P22

FFIEC IS

II.A.2II.C.10II.C.15(a)II.C.18

NYDFS 500

500.5

HIPAA Security Rule

§164.316(b)(2)(ii)

ECB CROE

CROE.2.3.4

EBA ICT Guidelines

3.4.43.5(a)

SEBI CSCRF

PR.ESPR.IP

BOT Cyber Resilience

Ch2.1

CMMC 2.0

CM

NERC CIP

CIP-010-4

10 CFR 73.54

RG5.71-B-CM

IEEE 1686-2022

5.4

DOE C2M2 v2.1

ASSET

API 1164

Sec 7

IAEA NSS 17-T

Sec 5.4

FIPS 140-3

FIPS 140-3 §7.2FIPS 140-3 §7.6

PCI HSM

8

Common Criteria

CC Part 2 — FMT

ISAE 3402

Clause 4

Solvency II

DR.266EIOPA-ICT-4.8

Lloyd's Minimum Standards

MS8.4

NAIC Insurance Data Security

4-config4B

PRA SS1/23

P3.3P-IT.3

FCA SYSC 13

SYSC 13.6.5SYSC 13.7.1

HITRUST CSF v11

09.a

FDA 21 CFR Part 11

§11.10(f)

FDA Cybersecurity Guidance

PU-2SPDF-3

ISO 27799

12.118.4

NHS DSPT

NDG-9.9

OWASP MASVS v2.1

MASVS-CODE-1MASVS-CRYPTO-1MASVS-CRYPTO-2

CCSS v9.0

1.02.6

MiCA

Art.62(1)Art.62(5)

Basel SCO60

SCO60.51SCO60.64SCO60.65

BSSC Standards

GSP-14NOS-03TIS-03

SEC Custody (Digital Assets)

SEC-CD-03SEC-CD-06SEC-CD-07SEC-CD-08

ISO 17799 (legacy)

None.

COBIT 4.1 (legacy)

None.