PR.PS-01: Configuration management practices are established and applied
Subcategory is new to this version of the framework and incorporates the following items from the previous version: PR.IP-1: A baseline configuration of information technology/industrial control systems is created and maintained incorporating security principles (e.g. concept of least functionality), PR.IP-3: Configuration change control processes are in place, PR.PT-2: Removable media is protected and its use restricted according to policy, PR.PT-3: The principle of least functionality is incorporated by configuring systems to provide only essential capabilities.
Description
[csf.tools Note: Subcategories do not have detailed descriptions. However NIST has provided the following implementation examples.]
Implementation Examples
1st: 1st Party Risk
Ex1: Establish, test, deploy, and maintain hardened baselines that enforce the organization's cybersecurity policies and provide only essential capabilities (i.e., principle of least functionality)
Ex2: Review all default configuration settings that may potentially impact cybersecurity when installing or upgrading software
Ex3: Monitor implemented software for deviations from approved baselines
Related Controls
NIST Special Publication 800-53 Revision 5.2.0
CM-1: Policy and Procedures
Develop, document, and disseminate to [Assignment: organization-defined personnel or roles]: [Assignment (one or more): organization-level, mission/business process-level, system-level] configuration management policy that: Addresses purpose, scope, roles, responsibilities, management commitment, coordination among organizational entities, and compliance; and Is consistent with applicable laws, executive orders, directives, regulations, policies, standards, and guidelines; and Procedures to facilitate the implementation…
CM-2: Baseline Configuration
Develop, document, and maintain under configuration control, a current baseline configuration of the system; and Review and update the baseline configuration of the system: [Assignment: organization-defined frequency]; When required due to [Assignment: organization-defined circumstances] ; and When system components are installed or upgraded.
CM-3: Configuration Change Control
Determine and document the types of changes to the system that are configuration-controlled; Review proposed configuration-controlled changes to the system and approve or disapprove such changes with explicit consideration for security and privacy impact analyses; Document configuration change decisions associated with the system; Implement approved configuration-controlled changes to the system; Retain records of configuration-controlled changes…
CM-4: Impact Analyses
Analyze changes to the system to determine potential security and privacy impacts prior to change implementation.
CM-5: Access Restrictions for Change
Define, document, approve, and enforce physical and logical access restrictions associated with changes to the system.
CM-6: Configuration Settings
Establish and document configuration settings for components employed within the system that reflect the most restrictive mode consistent with operational requirements using [Assignment: organization-defined common secure configurations]; Implement the configuration settings; Identify, document, and approve any deviations from established configuration settings for [Assignment: organization-defined system components] based on [Assignment: organization-defined operational requirements] ; and Monitor…
CM-7: Least Functionality
Configure the system to provide only [Assignment: organization-defined mission-essential capabilities] ; and Prohibit or restrict the use of the following functions, ports, protocols, software, and/or services: [Assignment: organization-defined prohibited or restricted functions, system ports, protocols, software, and/or services].
CM-8: System Component Inventory
Develop and document an inventory of system components that: Accurately reflects the system; Includes all components within the system; Does not include duplicate accounting of components or components assigned to any other system; Is at the level of granularity deemed necessary for tracking and reporting; and Includes the following information to achieve system component accountability:…
CM-9: Configuration Management Plan
Develop, document, and implement a configuration management plan for the system that: Addresses roles, responsibilities, and configuration management processes and procedures; Establishes a process for identifying configuration items throughout the system development life cycle and for managing the configuration of the configuration items; Defines the configuration items for the system and places the configuration items…
CM-10: Software Usage Restrictions
Use software and associated documentation in accordance with contract agreements and copyright laws; Track the use of software and associated documentation protected by quantity licenses to control copying and distribution; and Control and document the use of peer-to-peer file sharing technology to ensure that this capability is not used for the unauthorized distribution, display, performance,…
CM-11: User-installed Software
Establish [Assignment: organization-defined policies] governing the installation of software by users; Enforce software installation policies through the following methods: [Assignment: organization-defined methods] ; and Monitor policy compliance [Assignment: organization-defined frequency].
NIST SP 800-171 Revision 3.0
03.04.01: Baseline Configuration
Develop and maintain under configuration control, a current baseline configuration of the system. Review and update the baseline configuration of the system [Assignment: organization-defined frequency] and when system components are installed or modified.
03.04.02: Configuration Settings
Establish, document, and implement the following configuration settings for the system that reflect the most restrictive mode consistent with operational requirements: [Assignment: organization-defined configuration settings]. Identify, document, and approve any deviations from established configuration settings.
03.04.03: Configuration Change Control
Define the types of changes to the system that are configuration-controlled. Review proposed configuration-controlled changes to the system, and approve or disapprove such changes with explicit consideration for security impacts. Implement and document approved configuration-controlled changes to the system. Monitor and review activities associated with configuration-controlled changes to the system.
03.04.04: Impact Analyses
Analyze changes to the system to determine potential security impacts prior to change implementation. Verify that the security requirements for the system continue to be satisfied after the system changes have been implemented.
03.04.05: Access Restrictions for Change
Define, document, approve, and enforce physical and logical access restrictions associated with changes to the system.
03.04.06: Least Functionality
Configure the system to provide only mission-essential capabilities. Prohibit or restrict use of the following functions, ports, protocols, connections, and services: [Assignment: organization-defined functions, ports, protocols, connections, and services]. Review the system [Assignment: organization-defined frequency] to identify unnecessary or nonsecure functions, ports, protocols, connections, and services. Disable or remove functions, ports, protocols, connections, and services…
03.04.08: Authorized Software — Allow by Exception
Identify software programs authorized to execute on the system. Implement a deny-all, allow-by-exception policy for the execution of authorized software programs on the system. Review and update the list of authorized software programs [Assignment: organization-defined frequency].
03.04.10: System Component Inventory
Develop and document an inventory of system components. Review and update the system component inventory [Assignment: organization-defined frequency]. Update the system component inventory as part of installations, removals, and system updates.
03.04.12: System and Component Configuration for High-Risk Areas
Issue systems or system components with the following configurations to individuals traveling to high-risk locations: [Assignment: organization-defined system configurations]. Apply the following security requirements to the systems or components when the individuals return from travel: [Assignment: organization-defined security requirements].
03.15.01: Policy and Procedures
Develop, document, and disseminate to organizational personnel or roles the policies and procedures needed to satisfy the security requirements for the protection of CUI. Review and update policies and procedures [Assignment: organization-defined frequency].
Cloud Controls Matrix v4.0
AIS-02: Application Security Baseline Requirements
Establish, document and maintain baseline requirements for securing different applications.
AIS-04: Secure Application Design and Development
Define and implement a SDLC process for application design, development, deployment, and operation in accordance with security requirements defined by the organization.
AIS-05: Automated Application Security Testing
Implement a testing strategy, including criteria for acceptance of new information systems, upgrades and new versions, which provides application security assurance and maintains compliance while enabling organizational speed of delivery goals. Automate when applicable and possible.
AIS-06: Automated Secure Application Deployment
Establish and implement strategies and capabilities for secure, standardized, and compliant application deployment. Automate where possible.
CCC-01: Change Management Policy and Procedures
Establish, document, approve, communicate, apply, evaluate and maintain policies and procedures for managing the risks associated with applying changes to organization assets, including application, systems, infrastructure, configuration, etc., regardless of whether the assets are managed internally or externally (i.e., outsourced). Review and update the policies and procedures at least annually.
CCC-02: Quality Testing
Follow a defined quality change control, approval and testing process with established baselines, testing, and release standards.
CCC-06: Change Management Baseline
Establish change management baselines for all relevant authorized changes on organization assets.
CCC-07: Detection of Baseline Deviation
Implement detection measures with proactive notification in case of changes deviating from the established baseline.
IVS-04: OS Hardening and Base Controls
Harden host and guest OS, hypervisor or infrastructure control plane according to their respective best practices, and supported by technical controls, as part of a security baseline.
IVS-06: Segmentation and Segregation
Design, develop, deploy and configure applications and infrastructures such that CSP and CSC (tenant) user access and intra-tenant access is appropriately segmented and segregated, monitored and restricted from other tenants.
UEM-05: Endpoint Management
Define, implement and evaluate processes, procedures and technical measures to enforce policies and controls for all endpoints permitted to access systems and/or store, transmit, or process organizational data.
UEM-06: Automatic Lock Screen
Configure all relevant interactive-use endpoints to require an automatic lock screen.
UEM-07: Operating Systems
Manage changes to endpoint operating systems, patch levels, and/or applications through the company's change management processes.
UEM-09: Anti-Malware Detection and Prevention
Configure managed endpoints with anti-malware detection and prevention technology and services.
UEM-10: Software Firewall
Configure managed endpoints with properly configured software firewalls.
UEM-11: Data Loss Prevention
Configure managed endpoints with Data Loss Prevention (DLP) technologies and rules in accordance with a risk assessment.
UEM-12: Remote Locate
Enable remote geo-location capabilities for all managed mobile endpoints.
UEM-13: Remote Wipe
Define, implement and evaluate processes, procedures and technical measures to enable the deletion of company data remotely on managed endpoint devices.
Critical Security Controls Version 8.1
4.1: Establish and Maintain a Secure Configuration Process
Establish and maintain a secure configuration process for enterprise assets (end-user devices, including portable and mobile, non-computing/IoT devices, and servers) and software (operating systems and applications). Review and update documentation annually, or when significant enterprise changes occur that could impact this Safeguard.
4.2: Establish and Maintain a Secure Configuration Process for Network Infrastructure
Establish and maintain a secure configuration process for network devices. Review and update documentation annually, or when significant enterprise changes occur that could impact this Safeguard.