# CM-07 Least Functionality

NIST SP 800-53 control. Family: CM Configuration Management. Function: preventative. Baselines: low, moderate, high. Mapping licence: CC BY-SA 4.0.

Statement: a. Configure the system to provide only [Assignment: organization-defined mission essential capabilities]; and b. Prohibit or restrict the use of the following functions, ports, protocols, software, and/or services: [Assignment: organization-defined prohibited or restricted functions, system ports, protocols, software, and/or services].
Guidance: Systems provide a wide variety of functions and services. Some of the functions and services routinely provided by default may not be necessary to support essential organizational missions, functions, or operations. Additionally, it is sometimes convenient to provide multiple services from a single system component, but doing so increases risk over limiting the services provided by that single component. Where feasible, organizations limit component functionality to a single function per component. Organizations consider removing unused or unnecessary software and disabling unused or unnecessary physical and logical ports and protocols to prevent unauthorized connection of components, transfer of information, and tunneling. Organizations employ network scanning tools, intrusion detection and prevention systems, and end-point protection technologies, such as firewalls and host-based intrusion detection systems, to identify and prevent the use of prohibited functions, protocols, ports, and services. Least functionality can also be achieved as part of the fundamental design and development of the system (see SA-08, SC-02, and SC-03).

## Enhancements (9)
- CM-07(01) Periodic Review. Baselines: moderate, high
- CM-07(02) Prevent Program Execution. Baselines: moderate, high
- CM-07(03) Registration Compliance
- CM-07(04) Unauthorized Software — Deny-by-exception
- CM-07(05) Authorized Software — Allow-by-exception. Baselines: moderate, high
- CM-07(06) Confined Environments with Limited Privileges
- CM-07(07) Code Execution in Protected Environments
- CM-07(08) Binary or Machine Executable Code
- CM-07(09) Prohibiting The Use of Unauthorized Hardware
Each enhancement's statement: /api/v1/controls/CM-07?fields=enhancements

## Patterns that use it (13)
- Critical (4): SP-001 Client Module; SP-008 Public Web Server Pattern; SP-016 DMZ Module; SP-047 Secure Agentic AI Frameworks
- Important (5): SP-002 Server Module; SP-023 Industrial Control Systems; SP-028 Secure DevOps Pipeline Pattern; SP-030 API Security; SP-050 Mobile Security Architecture (draft)
- Standard (4): SP-037 Privileged User Management; SP-038 Vulnerability Management and Patching; SP-051 Tokenised Asset Security Architecture (draft); SP-053 Zero-Knowledge Proof Architecture (draft)

## Clauses by framework (69 frameworks)
- iso_27001_2022: A.8.1, A.8.9, A.8.18, A.8.19. OSA's own, not in NIST's crosswalk: A.8.1, A.8.9, A.8.18
- iso_27002_2022: 5.37, 8.1, 8.9, 8.18, 8.19
- cobit_2019: BAI10
- pci_dss_v4: 1.2.5, 2.2, 2.2.5
- nist_csf_2: PR.PS-01, PR.PS-02, PR.PS-05. OSA's own, not in NIST's crosswalk: PR.PS-02, PR.PS-05
- cis_controls_v8: CIS 2, CIS 2.3, CIS 2.5, CIS 2.6, CIS 2.7, CIS 4, CIS 4.8, CIS 9.1, CIS 9.4, CIS 10.3, CIS 12
- soc2_tsc: CC6.1-POF7, CC6.7-POF1
- finos_ccc: CCC-C14
- iso_42001_2023: A.9.4
- iec_62443: 3-3 SR 7.6, 3-3 SR 7.7
- asd_e8: E8-1, E8-1 ML1, E8-1 ML2, E8-1 ML3, E8-3, E8-3 ML1, E8-3 ML2, E8-3 ML3, E8-4, E8-4 ML1, E8-4 ML2, E8-4 ML3
- nis2: Art. 21(2)(g)
- mas_trm: 11
- bsi_grundschutz: APP.1.1, NET.1.2, NET.3.1, SYS.1.1, SYS.2.1
- anssi: Hygiene.18, Hygiene.20, SecNumCloud.13.1
- osfi_b13: B-13.2.2, B-13.3.2
- finma_circular: IV.A(28), IV.C(64), IV.C(65)
- gdpr: Art.25(1), Art.25(2), Art.32(1)(b)
- dora: Art.7(1), Art.9(1)
- bio2: 5.37, 8.1, 8.9, 8.18, 8.19
- rbi_csf: Annex1.2, Annex1.5
- fisc: FISC.T7, FISC.T14
- mlps_2: 8.1.4.4, 8.1.10.4
- dnb_good_practice: DNB.3.2, DNB.13.2, DNB.20.1
- cra: CRA.I.2b, CRA.I.2j, CRA.Info.8e
- swift_cscf: SWIFT.1.1, SWIFT.1.4, SWIFT.2.2, SWIFT.2.3, SWIFT.2.10
- cbuae: CR-7
- nca_ecc: 2-3, 2-6, 2-14, 5-1
- qatar_nia: OS
- sama_csf: 3.3, 3.5
- uae_ia: T7
- bog_cisd: CISD-VI
- bom_ctrm: 3.2, 3.12
- cbe_csf: CTO-6, CTO-7
- cbn_csf: Part3.3
- popia: s19
- sa_js2: JS2-7.2, JS2-8.4
- bot_cyber: Ch2.1, Ch2.6
- cpmi_pfmi: CG.PR
- eba_ict: 3.4.4
- ecb_croe: CROE.2.3.4
- ffiec_is: II.C.10, II.C.11, II.C.13(e), II.C.15(a)
- sebi_cscrf: PR.ES, PR.IP
- cmmc_2: CM
- nerc_cip: CIP-005-7, CIP-007-6
- nrc_73_54: RG5.71-B-CM
- ieee_1686: 5.6, 5.9
- ferc_cip: Order 887
- doe_c2m2: ASSET
- api_1164: Sec 7
- iaea_nss: Sec 5.4
- fips_140: FIPS 140-3 §7.6
- common_criteria: CC Part 2 — FMT
- isae_3402: Clause 4
- fca_sysc_13: SYSC 13.7.1
- fda_21_cfr_11: §11.10(f)
- hitrust_csf: 09.a
- iso_27799: 6.3
- lloyds_ms: MS8.4, MS8.10
- naic_ds: 4-config, 4B
- nhs_dspt: NDG-4.4
- solvency_ii: EIOPA-ICT-4.8
- owasp_masvs_v2: MASVS-PLATFORM-1, MASVS-PLATFORM-2
- csa_ccm_v4: UEM-02, UEM-10
- csa_aicm: UEM-02, UEM-10
- ccss_v9: 1.02.1, 1.05.4
- mica: Art.62(5), Art.68(1)
- basel_sco60: SCO60.51, SCO60.64, SCO60.65
- bssc: NOS-03, TIS-03
OSA's mapping for iso_27001_2022 and nist_csf_2 takes NIST's published crosswalk as its base. A clause not marked as OSA's own is in that crosswalk.

## More
- This control as JSON, with guidance and ATT&CK techniques: /api/v1/controls/CM-07
- Clauses only: /api/v1/controls/CM-07?fields=mappings
- Page for people: /controls/cm-07/
- Found an error? Open an issue at https://github.com/opensecurityarchitecture/osa-data/issues with the id, what OSA says and what the source says.
