Control statement
- a.Establish and document configuration settings for components employed within the system that reflect the most restrictive mode consistent with operational requirements using [Organization-defined: common secure configurations];
- b.Implement the configuration settings;
- c.Identify, document, and approve any deviations from established configuration settings for [Organization-defined: system components] based on [Organization-defined: operational requirements] ; and
- d.Monitor and control changes to the configuration settings in accordance with organizational policies and procedures.
Discussion
Configuration settings are the parameters that can be changed in the hardware, software, or firmware components of the system that affect the security and privacy posture or functionality of the system. Information technology products for which configuration settings can be defined include mainframe computers, servers, workstations, operating systems, mobile devices, input/output devices, protocols, and applications. Parameters that impact the security posture of systems include registry settings; account, file, or directory permission settings; and settings for functions, protocols, ports, services, and remote connections. Privacy parameters are parameters impacting the privacy posture of systems, including the parameters required to satisfy other privacy controls. Privacy parameters include settings for access controls, data processing preferences, and processing and retention permissions. Organizations establish organization-wide configuration settings and subsequently derive specific configuration settings for systems. The established settings become part of the configuration baseline for the system. Common secure configurations (also known as security configuration checklists, lockdown and hardening guides, and security reference guides) provide recognized, standardized, and established benchmarks that stipulate secure configuration settings for information technology products and platforms as well as instructions for configuring those products or platforms to meet operational requirements. Common secure configurations can be developed by a variety of organizations, including information technology product developers, manufacturers, vendors, federal agencies, consortia, academia, industry, and other organizations in the public and private sectors. Implementation of a common secure configuration may be mandated at the organization level, mission and business process level, system level, or at a higher level, including by a regulatory agency. Common secure configurations include the United States Government Configuration Baseline [USGCB](#98498928-3ca3-44b3-8b1e-f48685373087) and security technical implementation guides (STIGs), which affect the implementation of [CM-6](#cm-6) and other controls such as [AC-19](#ac-19) and [CM-7](#cm-7) . The Security Content Automation Protocol (SCAP) and the defined standards within the protocol provide an effective method to uniquely identify, track, and control configuration settings.
Organization-defined parameters
These values must be resolved through the organization’s tailoring and governance process. Bracketed parameter references in the control text identify where a decision is required.
From control text to operational evidence
Use Configuration Settings as a testable risk decision. Translate the official statement into accountable people, repeatable processes, configured technology, and evidence that demonstrates the outcome over time. In this family, pay particular attention to secure baselines, controlled change, configuration visibility, and drift management.
Implementation workflow
- Define the control boundary, responsible owner, inherited portions, and systems or processes in scope.
- Resolve each organization-defined parameter before declaring the control implemented.
- Document how the implementation satisfies every clause of the official control statement.
- Collect evidence as a normal byproduct of operation rather than only before an assessment.
- Review exceptions, changes, and monitoring results on a risk-based cadence.
Evidence examples
- approved baseline configurations
- change tickets and approvals
- configuration scans and drift reports
- software and hardware inventories
Common failure patterns
- baselines documented but not enforced
- emergency changes never reconciled
- asset inventories that omit cloud or ephemeral resources
- security-impact analysis performed after deployment
Questions practitioners should ask
- What risk decision is this control intended to support in this system?
- Which parts are implemented locally, inherited, shared, or not applicable—and what evidence supports that decision?
- Do the documented narrative, deployed configuration, operating process, and collected evidence agree?
- What event or threshold requires the implementation to be reviewed or changed?
Assessment objectives and methods
Show the assessment objective
- CM-06a.configuration settings that reflect the most restrictive mode consistent with operational requirements are established and documented for components employed within the system using [Organization-defined: common secure configurations];
- CM-06b.the configuration settings documented in CM-06a are implemented;
- CM-06c.
- CM-06c.[01]any deviations from established configuration settings for [Organization-defined: system components] are identified and documented based on [Organization-defined: operational requirements];
- CM-06c.[02]any deviations from established configuration settings for [Organization-defined: system components] are approved;
- CM-06d.
- CM-06d.[01]changes to the configuration settings are monitored in accordance with organizational policies and procedures;
- CM-06d.[02]changes to the configuration settings are controlled in accordance with organizational policies and procedures.
Examine
- Configuration management policy
- procedures addressing configuration settings for the system
- configuration management plan
- system design documentation
- system configuration settings and associated documentation
- common secure configuration checklists
- system component inventory
- evidence supporting approved deviations from established configuration settings
- change control records
- system data processing and retention permissions
- system audit records
- system security plan
- privacy plan
- other relevant documents or records
Interview
- Organizational personnel with security configuration management responsibilities
- organizational personnel with privacy configuration management responsibilities
- organizational personnel with information security and privacy responsibilities
- system/network administrators
Test
- Organizational processes for managing configuration settings
- mechanisms that implement, monitor, and/or control system configuration settings
- mechanisms that identify and/or document deviations from established configuration settings
Related controls
These relationships come from the official OSCAL catalog. They indicate useful dependencies or context, not automatic inheritance or equivalence.
Related defensive techniques
D3FEND maps this base control or one of its enhancements to the following defensive techniques. The ontology relation label is preserved and does not by itself prove implementation or effectiveness.
MITRE D3FEND™ and the D3FEND logo are trademarks of The MITRE Corporation. Bare Metal Cyber is not affiliated with or endorsed by MITRE.
Control enhancements
Enhancements add specificity, strength, or scope to the base control. Baseline badges show explicit selections in the official SP 800-53B OSCAL profiles.
CM-6(1) — Automated Management, Application, and Verification
Manage, apply, and verify configuration settings for [Organization-defined: system components] using [Organization-defined: organization-defined automated mechanisms].
Official discussion
Automated tools (e.g., hardening tools, baseline configuration tools) can improve the accuracy, consistency, and availability of configuration settings information. Automation can also provide data aggregation and data correlation capabilities, alerting mechanisms, and dashboards to support risk-based decision-making within the organization.
Organization-defined parameters (5)
Assessment objectives and methods
- CM-06(01)[01]configuration settings for [Organization-defined: system components] are managed using [Organization-defined: automated mechanisms];
- CM-06(01)[02]configuration settings for [Organization-defined: system components] are applied using [Organization-defined: automated mechanisms];
- CM-06(01)[03]configuration settings for [Organization-defined: system components] are verified using [Organization-defined: automated mechanisms].
Examine
- Configuration management policy
- procedures addressing configuration settings for the system
- configuration management plan
- system design documentation
- system configuration settings and associated documentation
- system component inventory
- common secure configuration checklists
- change control records
- system audit records
- system security plan
- privacy plan
- other relevant documents or records
Interview
- Organizational personnel with security configuration management responsibilities
- organizational personnel with information security and privacy responsibilities
- system/network administrators
- system developers
Test
- Organizational processes for managing configuration settings
- automated mechanisms implemented to manage, apply, and verify system configuration settings
Related controls
CM-6(2) — Respond to Unauthorized Changes
Take the following actions in response to unauthorized changes to [Organization-defined: configuration settings]: [Organization-defined: actions].
Official discussion
Responses to unauthorized changes to configuration settings include alerting designated organizational personnel, restoring established configuration settings, or—in extreme cases—halting affected system processing.
Organization-defined parameters (2)
Assessment objectives and methods
[Organization-defined: actions] are taken in response to unauthorized changes to [Organization-defined: configuration settings].
Examine
- System security plan
- privacy plan
- configuration management policy
- procedures addressing configuration settings for the system
- configuration management plan
- system design documentation
- system configuration settings and associated documentation
- alerts/notifications of unauthorized changes to system configuration settings
- system component inventory
- documented responses to unauthorized changes to system configuration settings
- change control records
- system audit records
- other relevant documents or records
Interview
- Organizational personnel with security configuration management responsibilities
- organizational personnel with security and privacy responsibilities
- system/network administrators
Test
- Organizational process for responding to unauthorized changes to system configuration settings
- mechanisms supporting and/or implementing actions in response to unauthorized changes
Related controls
CM-6(3) — Unauthorized Change Detection
This enhancement is marked withdrawn in the official OSCAL catalog. Related-control metadata below may identify where its intent was incorporated.
CM-6(4) — Conformance Demonstration
This enhancement is marked withdrawn in the official OSCAL catalog. Related-control metadata below may identify where its intent was incorporated.
Authoritative sources
Bare Metal Cyber is an independent educational publisher and is not affiliated with or endorsed by NIST. Official control requirements and interpretations remain with NIST and the responsible authorizing organization.