03.04: Configuration Management
Controls
03.04.01: Baseline Configuration
Develop and maintain under configuration control, a current baseline configuration of the system. Review and update the baseline configuration of the system [Assignment: organization-defined frequency] and when system components are installed or modified.
03.04.02: Configuration Settings
Establish, document, and implement the following configuration settings for the system that reflect the most restrictive mode consistent with operational requirements: [Assignment: organization-defined configuration settings]. Identify, document, and approve any deviations from established configuration settings.
03.04.03: Configuration Change Control
Define the types of changes to the system that are configuration-controlled. Review proposed configuration-controlled changes to the system, and approve or disapprove such changes with explicit consideration for security impacts. Implement and document approved configuration-controlled changes to the system. Monitor and review activities associated with configuration-controlled changes to the system.
03.04.04: Impact Analyses
Analyze changes to the system to determine potential security impacts prior to change implementation. Verify that the security requirements for the system continue to be satisfied after the system changes have been implemented.
03.04.05: Access Restrictions for Change
Define, document, approve, and enforce physical and logical access restrictions associated with changes to the system.
03.04.06: Least Functionality
Configure the system to provide only mission-essential capabilities. Prohibit or restrict use of the following functions, ports, protocols, connections, and services: [Assignment: organization-defined functions, ports, protocols, connections, and services]. Review the system [Assignment: organization-defined frequency] to identify unnecessary or nonsecure functions, ports, protocols, connections, and services. Disable or remove functions, ports, protocols, connections, and services…
03.04.08: Authorized Software — Allow by Exception
Identify software programs authorized to execute on the system. Implement a deny-all, allow-by-exception policy for the execution of authorized software programs on the system. Review and update the list of authorized software programs [Assignment: organization-defined frequency].
03.04.10: System Component Inventory
Develop and document an inventory of system components. Review and update the system component inventory [Assignment: organization-defined frequency]. Update the system component inventory as part of installations, removals, and system updates.
03.04.11: Information Location
Identify and document the location of CUI and the system components on which the information is processed and stored. Document changes to the system or system component location where CUI is processed and stored.
03.04.12: System and Component Configuration for High-Risk Areas
Issue systems or system components with the following configurations to individuals traveling to high-risk locations: [Assignment: organization-defined system configurations]. Apply the following security requirements to the systems or components when the individuals return from travel: [Assignment: organization-defined security requirements].