03.04.06: Least Functionality
Control Family:
CSF v2.0 References:
Previous Version:
- NIST Special Publication 800-171 Revision 2:
- 3.4.6: Employ the principle of least functionality by configuring organizational systems to provide only essential capabilities
Incorporates the following controls from the previous version of the control set: 3.4.7: Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services, 3.13.7: Prevent remote devices from simultaneously establishing non-remote connections with organizational systems and communicating via some other connection to resources in external networks (i.e., split tunneling).
Requirements
- Configure the system to provide only mission-essential capabilities.
- Prohibit or restrict use of the following functions, ports, protocols, connections, and services: [Assignment: organization-defined functions, ports, protocols, connections, and services].
- Review the system [Assignment: organization-defined frequency] to identify unnecessary or nonsecure functions, ports, protocols, connections, and services.
- Disable or remove functions, ports, protocols, connections, and services that are unnecessary or nonsecure.
Discussion
Systems can provide a variety of functions and services. Some functions and services that are routinely provided by default may not be necessary to support essential organizational missions, functions, or operations. It may be convenient to provide multiple services from single system components. However, doing so increases risk over limiting the services provided by any one component. Where feasible, organizations limit functionality to a single function per component. Organizations review the functions and services provided by the system or system components to determine which functions and services are candidates for elimination. Organizations disable unused or unnecessary physical and logical ports and protocols to prevent the unauthorized connection of devices, the transfer of information, and tunneling. Organizations can employ network scanning tools, intrusion detection and prevention systems, and endpoint protection systems (e.g., firewalls and host-based intrusion detection systems) to identify and prevent the use of prohibited functions, ports, protocols, system connections, and services. Bluetooth, File Transfer Protocol (FTP), and peer-to-peer networking are examples of the types of protocols that organizations consider eliminating, restricting, or disabling.