|
controlCM-7

Least Functionality (CM-7)

Configure the system to provide only [organization-defined] ; and Prohibit or restrict the use of the following functions, ports, protocols, software, and/or services: [organization-defined].

Security Baselines

LOWMODERATEHIGH
configurationbaselineschange-control

Why These Connect

Maps To3

These are equivalent or closely aligned requirements in other frameworks.

Baselined In3

This control is included in the linked security baseline (LOW, MODERATE, or HIGH).

Supports31

These related controls work together — a change to one may affect the others.

Mitigates8

This control helps defend against or reduce the risk of the linked threat technique.

Enhances9

These enhancements add specific capabilities or refinements to the base control.

Cross-Framework Mappings(3)

PR.PS-01PR.PS-01Final
NIST OLIR informative reference — Cybersecurity Framework v2.0 to SP 800-53 Rev 5
ISO 27001ISO/IEC 27001:20221 mappingFinal
NIST OLIR informative reference — SP 800-53 Rev 5 to ISO/IEC 27001:2022
PR.PS-01PR.PS-01Final
NIST OLIR informative reference — Cybersecurity Framework v2.0 to SP 800-53 Rev 5

Organization-Defined Parameters(6)

Assignmentorganization-defined mission-essential capabilities
Assignmentorganization-defined functions
Assignmentorganization-defined ports
Assignmentorganization-defined protocols
Assignmentorganization-defined software
Assignmentorganization-defined services

Control Enhancements(9)