03.04: Configuration Management

Controls

03.04.01: Baseline Configuration

Develop and maintain under configuration control, a current baseline configuration of the system. Review and update the baseline configuration of the system [Assignment: organization-defined frequency] and when system components are installed or modified.

03.04.02: Configuration Settings

Establish, document, and implement the following configuration settings for the system that reflect the most restrictive mode consistent with operational requirements: [Assignment: organization-defined configuration settings]. Identify, document, and approve any deviations from established configuration settings.

03.04.03: Configuration Change Control

Define the types of changes to the system that are configuration-controlled. Review proposed configuration-controlled changes to the system, and approve or disapprove such changes with explicit consideration for security impacts. Implement and document approved configuration-controlled changes to the system. Monitor and review activities associated with configuration-controlled changes to the system.

03.04.04: Impact Analyses

Analyze changes to the system to determine potential security impacts prior to change implementation. Verify that the security requirements for the system continue to be satisfied after the system changes have been implemented.

03.04.06: Least Functionality

Configure the system to provide only mission-essential capabilities. Prohibit or restrict use of the following functions, ports, protocols, connections, and services: [Assignment: organization-defined functions, ports, protocols, connections, and services]. Review the system [Assignment: organization-defined frequency] to identify unnecessary or nonsecure functions, ports, protocols, connections, and services. Disable or remove functions, ports, protocols, connections, and services…

03.04.08: Authorized Software — Allow by Exception

Identify software programs authorized to execute on the system. Implement a deny-all, allow-by-exception policy for the execution of authorized software programs on the system. Review and update the list of authorized software programs [Assignment: organization-defined frequency].

03.04.10: System Component Inventory

Develop and document an inventory of system components. Review and update the system component inventory [Assignment: organization-defined frequency]. Update the system component inventory as part of installations, removals, and system updates.

03.04.11: Information Location

Identify and document the location of CUI and the system components on which the information is processed and stored. Document changes to the system or system component location where CUI is processed and stored.

03.04.12: System and Component Configuration for High-Risk Areas

Issue systems or system components with the following configurations to individuals traveling to high-risk locations: [Assignment: organization-defined system configurations]. Apply the following security requirements to the systems or components when the individuals return from travel: [Assignment: organization-defined security requirements].