Back to catalog
CFG-03CFGConfiguration Management
Least Functionality
Description
Mechanisms exist to configure systems to provide only essential capabilities by specifically prohibiting or restricting the use of ports, protocols, and/or services.
Cross-Mappings
2142 paths across 4 frameworks
Cross-Mappings
NIST 800-531 mapping
CM-7
1.00
- Secure Controls Framework · 2026.2 · scf_strm · equivalent
NIST 800-1711 mapping
3.4.6
1.00
- Secure Controls Framework · 2026.2 · scf_strm · equivalent
- NIST · Rev 2 (Feb 2020, errata Jan 2021) · nist_800_171_app_d · equivalent
CCI4 mappings
CCI-000380
1.00
- Secure Controls Framework · 2026.2 · scf_strm · equivalent
- DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-000381
1.00
- Secure Controls Framework · 2026.2 · scf_strm · equivalent
- DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-000382
1.00
- Secure Controls Framework · 2026.2 · scf_strm · equivalent
- DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-003948
1.00
- Secure Controls Framework · 2026.2 · scf_strm · equivalent
- DISA · 2025-01-23 · disa_cci_list · equivalent
STIG1570 mappings
SV-101925r1_ruleThe MDM server platform must be protected by a DoD-approved firewall.
1.00
- Secure Controls Framework · 2026.2 · scf_strm · equivalent
- DISA · 2025-01-23 · disa_cci_list · equivalent
- DISA · V1R1 · disa_xccdf · related
SV-101927r1_ruleThe firewall protecting the MDM server platform must be configured to restrict all network traffic to and from all addresses with the exception of ports, protocols, and IP address ranges required to support MDM server and platform functions.
1.00
- Secure Controls Framework · 2026.2 · scf_strm · equivalent
- DISA · 2025-01-23 · disa_cci_list · equivalent
- DISA · V1R1 · disa_xccdf · related
SV-101929r1_ruleThe firewall protecting the MDM server platform must be configured so that only DoD-approved ports, protocols, and services are enabled. (See the DoD Ports, Protocols, Services Management [PPSM] Category Assurance Levels [CAL] list for DoD-approved ports, protocols, and services.)
1.00
- Secure Controls Framework · 2026.2 · scf_strm · equivalent
- DISA · 2025-01-23 · disa_cci_list · equivalent
- DISA · V1R1 · disa_xccdf · related
SV-102401r1_ruleThe SEL-2740S must be configured to permit the allowed and necessary ports, functions, protocols, and services.
1.00
- Secure Controls Framework · 2026.2 · scf_strm · equivalent
- DISA · 2025-01-23 · disa_cci_list · equivalent
- DISA · V1R1 · disa_xccdf · related
SV-104225r1_ruleSymantec ProxySG must not have unnecessary services and functions enabled.
1.00
- Secure Controls Framework · 2026.2 · scf_strm · equivalent
- DISA · 2025-01-23 · disa_cci_list · equivalent
- DISA · V1R3 · disa_xccdf · related
SV-104227r1_ruleSymantec ProxySG must be configured to remove or disable unrelated or unneeded application proxy services.
1.00
- Secure Controls Framework · 2026.2 · scf_strm · equivalent
- DISA · 2025-01-23 · disa_cci_list · equivalent
- DISA · V1R3 · disa_xccdf · related
SV-104229r1_ruleSymantec ProxySG must be configured to prohibit or restrict the use of network services as defined in the PPSM CAL and vulnerability assessments.
1.00
- Secure Controls Framework · 2026.2 · scf_strm · equivalent
- DISA · 2025-01-23 · disa_cci_list · equivalent
- DISA · V1R3 · disa_xccdf · related
SV-104525r1_ruleSymantec ProxySG must use only approved management services protocols.
1.00
- Secure Controls Framework · 2026.2 · scf_strm · equivalent
- DISA · 2025-01-23 · disa_cci_list · equivalent
- DISA · V1R2 · disa_xccdf · related
SV-202049r1043177_ruleThe network device must be configured to prohibit the use of all unnecessary and/or nonsecure functions, ports, protocols, and/or services
1.00
- Secure Controls Framework · 2026.2 · scf_strm · equivalent
- DISA · 2025-01-23 · disa_cci_list · equivalent
- DISA · V5R3 · disa_xccdf · related
SV-203637r958478_ruleThe operating system must be configured to disable non-essential capabilities.
1.00
- Secure Controls Framework · 2026.2 · scf_strm · equivalent
- DISA · 2025-01-23 · disa_cci_list · equivalent
- DISA · 3 · disa_xccdf · related
+1560 more (top 10 by confidence shown)
Control mappings provided by the Secure Controls Framework (SCF).
SCF
Powered by the Secure Controls Framework
The control catalog, cross-mappings, and STRM relationship data shown here are provided by the Secure Controls Framework (SCF), 2026.2. Every mapping is credited to SCF as the methodology, with the SCF reference and version stored alongside it.
© SCF Council, LLC. Secure Controls Framework content is free and shown here with attribution. securecontrolsframework.com · About SCF on STIGViewer