|
controlCM-6

Configuration Settings (CM-6)

Establish and document configuration settings for components employed within the system that reflect the most restrictive mode consistent with operational requirements using [organization-defined]; Implement the configuration settings; Identify, document, and approve any deviations from established configuration settings for [organization-defined] based on [organization-defined] ; and Monitor and control changes to the configuration settings in accordance with organizational policies and procedu

Security Baselines

LOWMODERATEHIGH
configurationbaselineschange-control

Why These Connect

Maps To5

These are equivalent or closely aligned requirements in other frameworks.

Baselined In3

This control is included in the linked security baseline (LOW, MODERATE, or HIGH).

Supports41

These related controls work together — a change to one may affect the others.

Mitigates8

This control helps defend against or reduce the risk of the linked threat technique.

Enhances4

These enhancements add specific capabilities or refinements to the base control.

Cross-Framework Mappings(5)

PR.PS-01PR.PS-01Final
NIST OLIR informative reference — Cybersecurity Framework v2.0 to SP 800-53 Rev 5
DE.CM-09DE.CM-09Final
NIST OLIR informative reference — Cybersecurity Framework v2.0 to SP 800-53 Rev 5
ISO 27001ISO/IEC 27001:20221 mappingFinal
NIST OLIR informative reference — SP 800-53 Rev 5 to ISO/IEC 27001:2022
PR.PS-01PR.PS-01Final
NIST OLIR informative reference — Cybersecurity Framework v2.0 to SP 800-53 Rev 5
DE.CM-09DE.CM-09Final
NIST OLIR informative reference — Cybersecurity Framework v2.0 to SP 800-53 Rev 5

Organization-Defined Parameters(3)

Assignmentorganization-defined common secure configurations
Assignmentorganization-defined system components
Assignmentorganization-defined operational requirements

Control Enhancements(4)