NIST 800-53 Rev 5

424 controls available

CM-6lowmoderatehigh

Configuration Settings

Configuration Management

Control Statement

Establish and document configuration settings for components employed within the system that reflect the most restrictive mode consistent with operational requirements using {{ insert: param, cm-06_odp.01 }}; Implement the configuration settings; Identify, document, and approve any deviations from established configuration settings for {{ insert: param, cm-06_odp.02 }} based on {{ insert: param, cm-06_odp.03 }} ; and Monitor and control changes to the configuration settings in accordance with organizational policies and procedures.

Discussion

Configuration settings are the parameters that can be changed in the hardware, software, or firmware components of the system that affect the security and privacy posture or functionality of the system. Information technology products for which configuration settings can be defined include mainframe computers, servers, workstations, operating systems, mobile devices, input/output devices, protocols, and applications. Parameters that impact the security posture of systems include registry settings; account, file, or directory permission settings; and settings for functions, protocols, ports, services, and remote connections. Privacy parameters are parameters impacting the privacy posture of systems, including the parameters required to satisfy other privacy controls. Privacy parameters include settings for access controls, data processing preferences, and processing and retention permissions. Organizations establish organization-wide configuration settings and subsequently derive specific configuration settings for systems. The established settings become part of the configuration baseline for the system. Common secure configurations (also known as security configuration checklists, lockdown and hardening guides, and security reference guides) provide recognized, standardized, and established benchmarks that stipulate secure configuration settings for information technology products and platforms as well as instructions for configuring those products or platforms to meet operational requirements. Common secure configurations can be developed by a variety of organizations, including information technology product developers, manufacturers, vendors, federal agencies, consortia, academia, industry, and other organizations in the public and private sectors. Implementation of a common secure configuration may be mandated at the organization level, mission and business process level, system level, or at a higher level, including by a regulatory agency. Common secure configurations include the United States Government Configuration Baseline [USGCB](#98498928-3ca3-44b3-8b1e-f48685373087) and security technical implementation guides (STIGs), which affect the implementation of [CM-6](#cm-6) and other controls such as [AC-19](#ac-19) and [CM-7](#cm-7) . The Security Content Automation Protocol (SCAP) and the defined standards within the protocol provide an effective method to uniquely identify, track, and control configuration settings.

Framework
NIST SP 800-53 Rev 5
Family
Configuration Management
Baselines
low, moderate, high

Related Frameworks

82 paths across 2 frameworks
NIST 800-1712 mappings
3.4.1
1.00
  • NIST · Rev 2 (Feb 2020, errata Jan 2021) · nist_800_171_app_d · equivalent
3.4.2
1.00
  • NIST · Rev 2 (Feb 2020, errata Jan 2021) · nist_800_171_app_d · equivalent
CCI49 mappings
CCI-000293
1.00
  • NIST · Rev 2 (Feb 2020, errata Jan 2021) · nist_800_171_app_d · equivalent
  • NIST · Rev 2 (Feb 2020, errata Jan 2021) · nist_800_171_app_d · equivalent
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-000294
1.00
  • NIST · Rev 2 (Feb 2020, errata Jan 2021) · nist_800_171_app_d · equivalent
  • NIST · Rev 2 (Feb 2020, errata Jan 2021) · nist_800_171_app_d · equivalent
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-000295
1.00
  • NIST · Rev 2 (Feb 2020, errata Jan 2021) · nist_800_171_app_d · equivalent
  • NIST · Rev 2 (Feb 2020, errata Jan 2021) · nist_800_171_app_d · equivalent
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-000296
1.00
  • NIST · Rev 2 (Feb 2020, errata Jan 2021) · nist_800_171_app_d · equivalent
  • NIST · Rev 2 (Feb 2020, errata Jan 2021) · nist_800_171_app_d · equivalent
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-000297
1.00
  • NIST · Rev 2 (Feb 2020, errata Jan 2021) · nist_800_171_app_d · equivalent
  • NIST · Rev 2 (Feb 2020, errata Jan 2021) · nist_800_171_app_d · equivalent
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-000363
1.00
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-000364
1.00
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-000365
1.00
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-000366
1.00
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-000367
1.00
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-000368
1.00
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-000369
1.00
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-000389
1.00
  • NIST · Rev 2 (Feb 2020, errata Jan 2021) · nist_800_171_app_d · equivalent
  • NIST · Rev 2 (Feb 2020, errata Jan 2021) · nist_800_171_app_d · equivalent
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-000390
1.00
  • NIST · Rev 2 (Feb 2020, errata Jan 2021) · nist_800_171_app_d · equivalent
  • NIST · Rev 2 (Feb 2020, errata Jan 2021) · nist_800_171_app_d · equivalent
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-000392
1.00
  • NIST · Rev 2 (Feb 2020, errata Jan 2021) · nist_800_171_app_d · equivalent
  • NIST · Rev 2 (Feb 2020, errata Jan 2021) · nist_800_171_app_d · equivalent
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-000393
1.00
  • NIST · Rev 2 (Feb 2020, errata Jan 2021) · nist_800_171_app_d · equivalent
  • NIST · Rev 2 (Feb 2020, errata Jan 2021) · nist_800_171_app_d · equivalent
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-000395
1.00
  • NIST · Rev 2 (Feb 2020, errata Jan 2021) · nist_800_171_app_d · equivalent
  • NIST · Rev 2 (Feb 2020, errata Jan 2021) · nist_800_171_app_d · equivalent
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-000396
1.00
  • NIST · Rev 2 (Feb 2020, errata Jan 2021) · nist_800_171_app_d · equivalent
  • NIST · Rev 2 (Feb 2020, errata Jan 2021) · nist_800_171_app_d · equivalent
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-000398
1.00
  • NIST · Rev 2 (Feb 2020, errata Jan 2021) · nist_800_171_app_d · equivalent
  • NIST · Rev 2 (Feb 2020, errata Jan 2021) · nist_800_171_app_d · equivalent
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-000399
1.00
  • NIST · Rev 2 (Feb 2020, errata Jan 2021) · nist_800_171_app_d · equivalent
  • NIST · Rev 2 (Feb 2020, errata Jan 2021) · nist_800_171_app_d · equivalent
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-000400
1.00
  • NIST · Rev 2 (Feb 2020, errata Jan 2021) · nist_800_171_app_d · equivalent
  • NIST · Rev 2 (Feb 2020, errata Jan 2021) · nist_800_171_app_d · equivalent
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-000408
1.00
  • NIST · Rev 2 (Feb 2020, errata Jan 2021) · nist_800_171_app_d · equivalent
  • NIST · Rev 2 (Feb 2020, errata Jan 2021) · nist_800_171_app_d · equivalent
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-000409
1.00
  • NIST · Rev 2 (Feb 2020, errata Jan 2021) · nist_800_171_app_d · equivalent
  • NIST · Rev 2 (Feb 2020, errata Jan 2021) · nist_800_171_app_d · equivalent
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-000410
1.00
  • NIST · Rev 2 (Feb 2020, errata Jan 2021) · nist_800_171_app_d · equivalent
  • NIST · Rev 2 (Feb 2020, errata Jan 2021) · nist_800_171_app_d · equivalent
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-001497
1.00
  • NIST · Rev 2 (Feb 2020, errata Jan 2021) · nist_800_171_app_d · equivalent
  • NIST · Rev 2 (Feb 2020, errata Jan 2021) · nist_800_171_app_d · equivalent
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-001502
1.00
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-001503
1.00
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-001585
1.00
  • NIST · Rev 2 (Feb 2020, errata Jan 2021) · nist_800_171_app_d · equivalent
  • NIST · Rev 2 (Feb 2020, errata Jan 2021) · nist_800_171_app_d · equivalent
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-001588
1.00
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-001755
1.00
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-001756
1.00
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-001779
1.00
  • NIST · Rev 2 (Feb 2020, errata Jan 2021) · nist_800_171_app_d · equivalent
  • NIST · Rev 2 (Feb 2020, errata Jan 2021) · nist_800_171_app_d · equivalent
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-001780
1.00
  • NIST · Rev 2 (Feb 2020, errata Jan 2021) · nist_800_171_app_d · equivalent
  • NIST · Rev 2 (Feb 2020, errata Jan 2021) · nist_800_171_app_d · equivalent
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-001781
1.00
  • NIST · Rev 2 (Feb 2020, errata Jan 2021) · nist_800_171_app_d · equivalent
  • NIST · Rev 2 (Feb 2020, errata Jan 2021) · nist_800_171_app_d · equivalent
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-001782
1.00
  • NIST · Rev 2 (Feb 2020, errata Jan 2021) · nist_800_171_app_d · equivalent
  • NIST · Rev 2 (Feb 2020, errata Jan 2021) · nist_800_171_app_d · equivalent
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-003909
1.00
  • NIST · Rev 2 (Feb 2020, errata Jan 2021) · nist_800_171_app_d · equivalent
  • NIST · Rev 2 (Feb 2020, errata Jan 2021) · nist_800_171_app_d · equivalent
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-003910
1.00
  • NIST · Rev 2 (Feb 2020, errata Jan 2021) · nist_800_171_app_d · equivalent
  • NIST · Rev 2 (Feb 2020, errata Jan 2021) · nist_800_171_app_d · equivalent
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-003941
1.00
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-003942
1.00
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-003943
1.00
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-003944
1.00
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-003945
1.00
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-003946
1.00
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-003962
1.00
  • NIST · Rev 2 (Feb 2020, errata Jan 2021) · nist_800_171_app_d · equivalent
  • NIST · Rev 2 (Feb 2020, errata Jan 2021) · nist_800_171_app_d · equivalent
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-003963
1.00
  • NIST · Rev 2 (Feb 2020, errata Jan 2021) · nist_800_171_app_d · equivalent
  • NIST · Rev 2 (Feb 2020, errata Jan 2021) · nist_800_171_app_d · equivalent
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-003964
1.00
  • NIST · Rev 2 (Feb 2020, errata Jan 2021) · nist_800_171_app_d · equivalent
  • NIST · Rev 2 (Feb 2020, errata Jan 2021) · nist_800_171_app_d · equivalent
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-003965
1.00
  • NIST · Rev 2 (Feb 2020, errata Jan 2021) · nist_800_171_app_d · equivalent
  • NIST · Rev 2 (Feb 2020, errata Jan 2021) · nist_800_171_app_d · equivalent
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-003966
1.00
  • NIST · Rev 2 (Feb 2020, errata Jan 2021) · nist_800_171_app_d · equivalent
  • NIST · Rev 2 (Feb 2020, errata Jan 2021) · nist_800_171_app_d · equivalent
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-003967
1.00
  • NIST · Rev 2 (Feb 2020, errata Jan 2021) · nist_800_171_app_d · equivalent
  • NIST · Rev 2 (Feb 2020, errata Jan 2021) · nist_800_171_app_d · equivalent
  • DISA · 2025-01-23 · disa_cci_list · equivalent

Related STIGs

374 STIGs reach this control through 26 CCIs. Expand a row to see the responsible NICE and O*NET roles.

Operating System — Desktop

10 STIGs
Show 2 more STIGs in this category →

Operating System — Server

47 STIGs
Oracle Linux 9 Security Technical Implementation Guide
12025-05-08148 of 456 findings match
Oracle Linux 9 Security Technical Implementation Guide
V1R52026-02-17145 of 448 findings match
Solaris 11 SPARC Security Technical Implementation Guide
V3R52026-02-19124 of 217 findings match
Show 39 more STIGs in this category →
Solaris 11 X86 Security Technical Implementation Guide
V3R52026-02-19123 of 216 findings match
Solaris 11 X86 Security Technical Implementation Guide
32025-05-05123 of 216 findings match
IBM AIX 7.x Security Technical Implementation Guide
V3R22026-02-06121 of 283 findings match
IBM AIX 7.x Security Technical Implementation Guide
32024-08-16121 of 283 findings match
Oracle Linux 8 Security Technical Implementation Guide
22025-05-13121 of 374 findings match
Oracle Linux 8 Security Technical Implementation Guide
V2R82026-02-13120 of 375 findings match
Anduril NixOS Security Technical Implementation Guide
V1R22025-08-198 of 103 findings match

Operating System — Mainframe

20 STIGs
IBM z/OS ACF2 Security Technical Implementation Guide
V9R82026-03-0936 of 225 findings match
IBM z/OS RACF Security Technical Implementation Guide
V9R82026-03-0928 of 222 findings match
IBM z/OS TSS Security Technical Implementation Guide
V9R82026-03-0928 of 230 findings match
IBM z/OS TSS Security Technical Implementation Guide
92025-06-2428 of 231 findings match
Show 12 more STIGs in this category →
Mainframe Product Security Requirements Guide
V3R42025-09-101 of 194 findings match
Mainframe Product Security Requirements Guide
32024-12-051 of 193 findings match

Operating System — Mobile

40 STIGs
Show 32 more STIGs in this category →

Network Device

130 STIGs
BIND 9.x Security Technical Implementation Guide
V3R22026-02-2542 of 73 findings match
BIND 9.x Security Technical Implementation Guide
22024-02-1537 of 70 findings match
Domain Name System (DNS) Security Requirements Guide
42024-07-0232 of 118 findings match
Show 122 more STIGs in this category →
Domain Name System (DNS) Security Requirements Guide
V4R22025-12-1916 of 119 findings match
Router Security Requirements Guide
V5R22025-09-1015 of 123 findings match
Router Security Requirements Guide
52024-05-2815 of 108 findings match
Riverbed NetIM OS Security Technical Implementation Guide
V1R12025-10-0214 of 154 findings match
Application Layer Gateway Security Requirements Guide
V2R32025-09-1513 of 160 findings match
Layer 2 Switch Security Requirements Guide
V3R42026-02-1213 of 36 findings match
Layer 2 Switch Security Requirements Guide
32025-03-0513 of 28 findings match
AAA Services Security Requirements Guide
V2R22024-12-048 of 77 findings match
Cisco ISE NDM Security Technical Implementation Guide
V2R32025-12-115 of 53 findings match
Network Device Management Security Requirements Guide
V5R32025-02-115 of 104 findings match
Network Device Management Security Requirements Guide
V5R42025-09-105 of 105 findings match
SDN Controller Security Requirements Guide
22024-05-285 of 34 findings match
Firewall Security Requirements Guide
V3R32025-09-224 of 35 findings match
Firewall Security Requirements Guide
32024-12-044 of 34 findings match
SEL-2740S L2S Security Technical Implementation Guide
V1R12019-05-064 of 13 findings match
SEL-2740S NDM Security Technical Implementation Guide
V1R12019-05-064 of 13 findings match
Cisco ISE NAC Security Technical Implementation Guide
V2R32025-12-103 of 30 findings match
RUCKUS ICX NDM Security Technical Implementation Guide
V1R12025-05-283 of 25 findings match
Cisco ACI NDM Security Technical Implementation Guide
V1R22025-12-112 of 26 findings match
Cisco ASA NDM Security Technical Implementation Guide
V2R42025-12-081 of 47 findings match
Cisco ASA VPN Security Technical Implementation Guide
V2R22024-08-221 of 41 findings match

Database

13 STIGs
Database Security Requirements Guide
V4R52026-02-261 of 142 findings match
Database Security Requirements Guide
42024-12-041 of 142 findings match
Show 5 more STIGs in this category →

Web / Application Server

25 STIGs
Show 17 more STIGs in this category →
Web Server Security Requirements Guide
V4R42025-09-102 of 126 findings match
Web Server Security Requirements Guide
42025-02-122 of 124 findings match
Application Server Security Requirements Guide
V4R42025-09-101 of 137 findings match
Application Server Security Requirements Guide
42025-02-111 of 128 findings match

Virtualization / Container

45 STIGs
Show 37 more STIGs in this category →
Kubernetes Security Technical Implementation Guide
V2R62026-02-1224 of 92 findings match
Kubernetes Security Technical Implementation Guide
22025-05-1624 of 94 findings match
Container Platform Security Requirements Guide
V2R42025-09-104 of 188 findings match
Container Platform Security Requirements Guide
22025-05-154 of 187 findings match
Virtual Machine Manager Security Requirements Guide
22024-12-062 of 193 findings match
Virtual Machine Manager Security Requirements Guide
V2R32025-09-102 of 198 findings match

Cloud / Identity Service

3 STIGs

Endpoint Security Management

29 STIGs
Central Log Server Security Requirements Guide
V3R42026-02-128 of 127 findings match
Central Log Server Security Requirements Guide
32024-12-048 of 125 findings match
Tanium 7.x Security Technical Implementation Guide
V2R32025-05-146 of 98 findings match
ISEC7 Sphere Security Technical Implementation Guide
V3R12024-08-204 of 34 findings match
Show 21 more STIGs in this category →
BlackBerry UEM Security Technical Implementation Guide
V2R12020-12-043 of 16 findings match
HYCU Protege Security Technical Implementation Guide
V1R22026-03-043 of 55 findings match

Productivity Application

6 STIGs

Uncategorized

6 STIGs