← Controls / CM

CM-07 Least Functionality

Configuration Management

Low Moderate High

Description

a. Configure the system to provide only [Assignment: organization-defined mission essential capabilities]; and b. Prohibit or restrict the use of the following functions, ports, protocols, software, and/or services: [Assignment: organization-defined prohibited or restricted functions, system ports, protocols, software, and/or services].

Supplemental Guidance

Systems provide a wide variety of functions and services. Some of the functions and services routinely provided by default may not be necessary to support essential organizational missions, functions, or operations. Additionally, it is sometimes convenient to provide multiple services from a single system component, but doing so increases risk over limiting the services provided by that single component. Where feasible, organizations limit component functionality to a single function per component. Organizations consider removing unused or unnecessary software and disabling unused or unnecessary physical and logical ports and protocols to prevent unauthorized connection of components, transfer of information, and tunneling. Organizations employ network scanning tools, intrusion detection and prevention systems, and end-point protection technologies, such as firewalls and host-based intrusion detection systems, to identify and prevent the use of prohibited functions, protocols, ports, and services. Least functionality can also be achieved as part of the fundamental design and development of the system (see SA-08, SC-02, and SC-03).

Changes from Rev 4

Adds parameter text for 'mission' essential capabilities Discussion expanded slightly

Enhancements (9)

What NIST adds to this control. Select one to read its statement.

CM-07(01) Periodic Review ModerateHigh

a. Review the system [Assignment: organization-defined frequency] to identify unnecessary and/or nonsecure functions, ports, protocols, software, and services; and b. Disable or remove [Assignment: organization-defined functions, ports, protocols, software, and services within the system deemed to be unnecessary and/or nonsecure].

CM-07(02) Prevent Program Execution ModerateHigh

Prevent program execution in accordance with [Selection (one or more): [Assignment: organization-defined policies, rules of behavior, and/or access agreements regarding software program usage and restrictions]; rules authorizing the terms and conditions of software program usage].

CM-07(03) Registration Compliance

Ensure compliance with [Assignment: organization-defined registration requirements for functions, ports, protocols, and services].

CM-07(04) Unauthorized Software — Deny-by-exception

a. Identify [Assignment: organization-defined software programs not authorized to execute on the system]; b. Employ an allow-all, deny-by-exception policy to prohibit the execution of unauthorized software programs on the system; and c. Review and update the list of unauthorized software programs [Assignment: organization-defined frequency].

CM-07(05) Authorized Software — Allow-by-exception ModerateHigh

a. Identify [Assignment: organization-defined software programs authorized to execute on the system]; b. Employ a deny-all, permit-by-exception policy to allow the execution of authorized software programs on the system; and c. Review and update the list of authorized software programs [Assignment: organization-defined frequency].

CM-07(06) Confined Environments with Limited Privileges

Require that the following user-installed software execute in a confined physical or virtual machine environment with limited privileges: [Assignment: organization-defined user-installed software].

CM-07(07) Code Execution in Protected Environments

Allow execution of binary or machine-executable code only in confined physical or virtual machine environments and with the explicit approval of [Assignment: organization-defined personnel or roles] when such code is: a. Obtained from sources with limited or no warranty; and/or b. Without the provision of source code.

CM-07(08) Binary or Machine Executable Code

a. Prohibit the use of binary or machine-executable code from sources with limited or no warranty or without the provision of source code; and b. Allow exceptions only for compelling mission or operational requirements and with the approval of the authorizing official.

CM-07(09) Prohibiting The Use of Unauthorized Hardware

a. Identify [Assignment: organization-defined hardware components authorized for system use]; b. Prohibit the use or connection of unauthorized hardware components; c. Review and update the list of authorized hardware components [Assignment: organization-defined frequency].

MITRE ATT&CK Techniques (225)

ATT&CK v16.1

Techniques mitigated by this control, mapped via CTID.

Reconnaissance 1 Initial Access 8 Execution 24 Persistence 46 Privilege Escalation 37 Defense Evasion 79 Credential Access 20 Discovery 9 Lateral Movement 14 Collection 13 Command & Control 26 Exfiltration 10 Impact 12
Show all 225 techniques grouped by tactic

Reconnaissance

Persistence

Privilege Escalation

Defense Evasion

T1027 T1036 T1078 T1112 T1127 T1197 T1205 T1216 T1218 T1220 T1221 T1484 T1548 T1553 T1556 T1562 T1574 T1599 T1601 T1610 T1612 T1622 T1647 T1036.005 T1036.007 T1036.008 T1078.004 T1127.002 T1205.001 T1216.001 T1216.002 T1218.001 T1218.002 T1218.003 T1218.004 T1218.005 T1218.007 T1218.008 T1218.009 T1218.012 T1218.013 T1218.014 T1218.015 T1542.004 T1542.005 T1548.001 T1548.003 T1548.004 T1548.006 T1553.001 T1553.003 T1553.004 T1553.005 T1553.006 T1556.002 T1556.008 T1556.009 T1562.001 T1562.002 T1562.003 T1562.004 T1562.006 T1562.009 T1562.010 T1564.002 T1564.003 T1564.006 T1564.008 T1564.009 T1574.001 T1574.006 T1574.007 T1574.008 T1574.009 T1574.012 T1574.014 T1599.001 T1601.001 T1601.002

Compliance Mappings

ISO 27001:2022

A.8.1A.8.9A.8.18A.8.19

ISO 27002:2022

5.378.18.98.188.19

COBIT 2019

BAI10

CIS Controls v8

CIS 2CIS 2.3CIS 2.5CIS 2.6CIS 2.7CIS 4CIS 4.8CIS 9.1CIS 9.4CIS 10.3CIS 12

NIST CSF 2.0

PR.PS-01PR.PS-02PR.PS-05

SOC 2 TSC

CC6.1-POF7CC6.7-POF1

PCI DSS v4.0.1

1.2.52.22.2.5

CSA CCM v4

UEM-02UEM-10

CSA AICM v1

UEM-02UEM-10

FINOS CCC

CCC-C14

ISO 42001:2023

A.9.4

IEC 62443

3-3 SR 7.63-3 SR 7.7

NIS2 Directive

Art. 21(2)(g)

MAS TRM

11

ASD Essential Eight

E8-1E8-1 ML1E8-1 ML2E8-1 ML3E8-3E8-3 ML1E8-3 ML2E8-3 ML3E8-4E8-4 ML1E8-4 ML2E8-4 ML3

BSI IT-Grundschutz

APP.1.1NET.1.2NET.3.1SYS.1.1SYS.2.1

ANSSI

Hygiene.18Hygiene.20SecNumCloud.13.1

FINMA Circular 2023/1

IV.A(28)IV.C(64)IV.C(65)

OSFI B-13

B-13.2.2B-13.3.2

EU GDPR

Art.25(1)Art.25(2)Art.32(1)(b)

EU DORA

Art.7(1)Art.9(1)

BIO2

5.378.18.98.188.19

RBI CSF

Annex1.2Annex1.5

FISC Security Guidelines

FISC.T7FISC.T14

MLPS 2.0

8.1.4.48.1.10.4

DNB Good Practice

DNB.3.2DNB.13.2DNB.20.1

EU CRA

CRA.I.2bCRA.I.2jCRA.Info.8e

SWIFT CSCF

SWIFT.1.1SWIFT.1.4SWIFT.2.2SWIFT.2.3SWIFT.2.10

SAMA CSF

3.33.5

NCA ECC

2-32-62-145-1

UAE IA

T7

Qatar NIA

OS

CBUAE

CR-7

CBE CSF

CTO-6CTO-7

SA JS2

JS2-7.2JS2-8.4

CBN CSF

Part3.3

BoG CISD

CISD-VI

POPIA

s19

BoM CTRM

3.23.12

CPMI-IOSCO PFMI

CG.PR

FFIEC IS

II.C.10II.C.11II.C.13(e)II.C.15(a)

ECB CROE

CROE.2.3.4

EBA ICT Guidelines

3.4.4

SEBI CSCRF

PR.ESPR.IP

BOT Cyber Resilience

Ch2.1Ch2.6

CMMC 2.0

CM

NERC CIP

CIP-005-7CIP-007-6

10 CFR 73.54

RG5.71-B-CM

IEEE 1686-2022

5.65.9

FERC CIP Orders

Order 887

DOE C2M2 v2.1

ASSET

API 1164

Sec 7

IAEA NSS 17-T

Sec 5.4

FIPS 140-3

FIPS 140-3 §7.6

Common Criteria

CC Part 2 — FMT

ISAE 3402

Clause 4

Solvency II

EIOPA-ICT-4.8

Lloyd's Minimum Standards

MS8.4MS8.10

NAIC Insurance Data Security

4-config4B

FCA SYSC 13

SYSC 13.7.1

HITRUST CSF v11

09.a

FDA 21 CFR Part 11

§11.10(f)

ISO 27799

6.3

NHS DSPT

NDG-4.4

OWASP MASVS v2.1

MASVS-PLATFORM-1MASVS-PLATFORM-2

CCSS v9.0

1.02.11.05.4

MiCA

Art.62(5)Art.68(1)

Basel SCO60

SCO60.51SCO60.64SCO60.65

BSSC Standards

NOS-03TIS-03

ISO 17799 (legacy)

None.

COBIT 4.1 (legacy)

None.