Knowledge is Power

Sitewide Search

Search Bare Metal Cyber

Search courses, individual lessons, wiki entries, books, podcasts, magazine articles, Daily Cyber News, and Darwin.

NIST SP 800-172 Enhanced CUI Protection Center

03.04 — Configuration Management

Study this CUI requirement family as a connected set of implementation decisions, evidence expectations, and assessment procedures.

7Active requirements
1Withdrawn records
13Parameters
17Assessment objectives

CUI requirement family

Configuration Management

Use this family as a planning boundary, but assess every applicable requirement against the real CUI system boundary, inherited services, organization-defined parameters, and operational evidence.

7 active1 withdrawnRevision 3
CM

Family catalog

Requirements and assessment procedures.

Withdrawn records remain available and link to the requirements where their intent was incorporated or addressed.

03.04.01EWithdrawn

Withdrawn requirement

Withdrawn NIST SP 800-172 Rev. 3 requirement 03.04.01E; use the recorded replacement relationships.

03.04.02EActive

Automated Unauthorized Component Detection

Monitoring for unauthorized or misconfigured components may be accomplished on an ongoing basis or by the periodic scanning of systems for that purpose. Automated mechanisms may also be used to prevent the connection of unauthorized or misconfigured system components. Automated mechanisms can be implemented in systems or in separate system components. When acquiring and implementing automated mechanisms, organization

03.04.03EActive

Automated Maintenance of System Component Inventory

The system component inventory includes system-specific information required for component accountability and to provide support to identify, control, monitor, and verify configuration items based on the authoritative source. The information necessary for the accountability of system components includes the system name, hardware and software component owners, hardware inventory specifications, software license inform

03.04.04EActive

Automation Support for Baseline Configuration

Automated mechanisms that help organizations maintain consistent baseline configurations for systems include configuration management tools; hardware, software, and firmware inventory tools; and network management tools. Automated tools can be used to track version numbers on operating systems, applications, the types of software installed, and current patch levels. Automation support for accuracy and currency can be

03.04.05EActive

Dual Authorization for System Changes

Dual authorization is also known as two-person control. Organizations employ dual authorization to help ensure that any changes to selected system components and system-level information cannot occur unless two qualified individuals approve and implement such changes. Requiring two individuals to implement system changes provides an increased level of assurance that the proposed changes are correct implementations of

03.04.06EActive

Retention of Previous Configurations

Retaining previous versions of baseline configurations to support rollback includes configuration files for hardware, software, and firmware, configuration records, and associated documentation. This requirement enhances SP 800-171 requirement 03.04.01.

03.04.07EActive

Testing, Validation, and Documentation of Changes

Changes to systems include modifications to hardware, software, or firmware components and defined configuration settings. Organizations ensure that testing does not interfere with system operations that support organizational missions and business functions. Individuals or groups that conduct the tests understand the system security policies and procedures associated with the specific facilities or processes. Operat

03.04.08EActive

Centralized Repository

Organizations may implement centralized system component inventories that include components from all organizational systems. Centralized repositories of component inventories provide opportunities for efficiencies in accounting for organizational hardware, software, and firmware assets. Such repositories can help organizations rapidly identify the location and responsible individuals of system components that have b