Doc:NIST SP 800-53Ar1 Appendix F/Enhanced/CM
From FISMApedia
NIST SP 800-53Ar1 Assessment Procedure Catalog, with SP 800-53r3 Security Controls
CONFIGURATION MANAGEMENT
CM-1 CONFIGURATION MANAGEMENT POLICY AND PROCEDURES
| FAMILY: CONFIGURATION MANAGEMENT | CLASS: OPERATIONAL |
- Security Control Baseline:
| CM-1 | Configuration Management Policy and Procedures | P1 | LOW CM-1 | MOD CM-1 | HIGH CM-1 |
| SECURITY CONTROL |
|---|
|
CM-1 CONFIGURATION MANAGEMENT POLICY AND PROCEDURES
|
| ASSESSMENT PROCEDURE | ||
|---|---|---|
| CM-1 | CONFIGURATION MANAGEMENT POLICY AND PROCEDURES | |
| CM-1.1 | ASSESSMENT OBJECTIVE:
| |
| CM-1.2 | ASSESSMENT OBJECTIVE:
| |
CM-2 BASELINE CONFIGURATION
| FAMILY: CONFIGURATION MANAGEMENT | CLASS: OPERATIONAL |
- Security Control Baseline:
| CM-2 | Baseline Configuration | P1 | LOW CM-2 | MOD CM-2 (1) (3) (4) | HIGH CM-2 (1) (2) (3) (5) (6) |
| SECURITY CONTROL |
|---|
|
CM-2 BASELINE CONFIGURATION
|
| ASSESSMENT PROCEDURE | ||
|---|---|---|
| CM-2 | BASELINE CONFIGURATION | |
| CM-2.1 | ASSESSMENT OBJECTIVE:
| |
| SECURITY CONTROL ENHANCEMENT |
|---|
|
| CM-2(1) | BASELINE CONFIGURATION | |
| CM-2(1).1 | ASSESSMENT OBJECTIVE:
|
| SECURITY CONTROL ENHANCEMENT |
|---|
|
| CM-2(2) | BASELINE CONFIGURATION | |
| CM-2(2).1 | ASSESSMENT OBJECTIVE:
|
| SECURITY CONTROL ENHANCEMENT |
|---|
|
| CM-2(3) | BASELINE CONFIGURATION | |
| CM-2(3).1 | ASSESSMENT OBJECTIVE:
|
| SECURITY CONTROL ENHANCEMENT |
|---|
|
| CM-2(4) | BASELINE CONFIGURATION | |
| CM-2(4).1 | ASSESSMENT OBJECTIVE:
|
| SECURITY CONTROL ENHANCEMENT |
|---|
|
| CM-2(5) | BASELINE CONFIGURATION | |
| CM-2(5).1 | ASSESSMENT OBJECTIVE:
|
| SECURITY CONTROL ENHANCEMENT |
|---|
|
| CM-2(6) | BASELINE CONFIGURATION | |
| CM-2(6).1 | ASSESSMENT OBJECTIVE:
|
CM-3 CONFIGURATION CHANGE CONTROL
| FAMILY: CONFIGURATION MANAGEMENT | CLASS: OPERATIONAL |
- Security Control Baseline:
| CM-3 | Configuration Change Control | P1 | LOW Not Selected | MOD CM-3 (2) | HIGH CM-3 (1) (2) |
| SECURITY CONTROL |
|---|
|
CM-3 CONFIGURATION CHANGE CONTROL
|
| ASSESSMENT PROCEDURE | ||
|---|---|---|
| CM-3 | CONFIGURATION CHANGE CONTROL | |
| CM-3.1 | ASSESSMENT OBJECTIVE:
| |
| SECURITY CONTROL ENHANCEMENT |
|---|
|
| CM-3(1) | CONFIGURATION CHANGE CONTROL | |
| CM-3(1).1 | ASSESSMENT OBJECTIVE:
|
| SECURITY CONTROL ENHANCEMENT |
|---|
|
| CM-3(2) | CONFIGURATION CHANGE CONTROL | |
| CM-3(2).1 | ASSESSMENT OBJECTIVE:
|
| SECURITY CONTROL ENHANCEMENT |
|---|
|
| CM-3(3) | CONFIGURATION CHANGE CONTROL | |
| CM-3(3).1 | ASSESSMENT OBJECTIVE:
|
| SECURITY CONTROL ENHANCEMENT |
|---|
|
| CM-3(4) | CONFIGURATION CHANGE CONTROL | |
| CM-3(4).1 | ASSESSMENT OBJECTIVE:
|
CM-4 SECURITY IMPACT ANALYSIS
| FAMILY: CONFIGURATION MANAGEMENT | CLASS: OPERATIONAL |
- Security Control Baseline:
| CM-4 | Security Impact Analysis | P2 | LOW CM-4 | MOD CM-4 | HIGH CM-4 (1) |
| SECURITY CONTROL |
|---|
|
CM-4 SECURITY IMPACT ANALYSIS
|
| ASSESSMENT PROCEDURE | ||
|---|---|---|
| CM-4 | SECURITY IMPACT ANALYSIS | |
| CM-4.1 | ASSESSMENT OBJECTIVE:
| |
| SECURITY CONTROL ENHANCEMENT |
|---|
|
| CM-4(1) | SECURITY IMPACT ANALYSIS | |
| CM-4(1).1 | ASSESSMENT OBJECTIVE:
|
| SECURITY CONTROL ENHANCEMENT |
|---|
|
| CM-4(2) | SECURITY IMPACT ANALYSIS | |
| CM-4(2).1 | ASSESSMENT OBJECTIVE:
|
CM-5 ACCESS RESTRICTIONS FOR CHANGE
| FAMILY: CONFIGURATION MANAGEMENT | CLASS: OPERATIONAL |
- Security Control Baseline:
| CM-5 | Access Restrictions for Change | P1 | LOW Not Selected | MOD CM-5 | HIGH CM-5 (1) (2) (3) |
| SECURITY CONTROL |
|---|
|
CM-5 ACCESS RESTRICTIONS FOR CHANGE
|
| ASSESSMENT PROCEDURE | ||
|---|---|---|
| CM-5 | ACCESS RESTRICTIONS FOR CHANGE | |
| CM-5.1 | ASSESSMENT OBJECTIVE:
| |
| SECURITY CONTROL ENHANCEMENT |
|---|
|
| CM-5(1) | ACCESS RESTRICTIONS FOR CHANGE | |
| CM-5(1).1 | ASSESSMENT OBJECTIVE:
|
| SECURITY CONTROL ENHANCEMENT |
|---|
|
| CM-5(2) | ACCESS RESTRICTIONS FOR CHANGE | |
| CM-5(2).1 | ASSESSMENT OBJECTIVE:
|
| SECURITY CONTROL ENHANCEMENT |
|---|
|
| CM-5(3) | ACCESS RESTRICTIONS FOR CHANGE | |
| CM-5(3).1 | ASSESSMENT OBJECTIVE:
|
| SECURITY CONTROL ENHANCEMENT |
|---|
|
| CM-5(4) | ACCESS RESTRICTIONS FOR CHANGE | |
| CM-5(4).1 | ASSESSMENT OBJECTIVE:
|
| SECURITY CONTROL ENHANCEMENT |
|---|
|
| CM-5(5) | ACCESS RESTRICTIONS FOR CHANGE | |
| CM-5(5).1 | ASSESSMENT OBJECTIVE:
|
| SECURITY CONTROL ENHANCEMENT |
|---|
|
| CM-5(6) | ACCESS RESTRICTIONS FOR CHANGE | |
| CM-5(6).1 | ASSESSMENT OBJECTIVE:
|
| SECURITY CONTROL ENHANCEMENT |
|---|
|
| CM-5(7) | ACCESS RESTRICTIONS FOR CHANGE | |
| CM-5(7).1 | ASSESSMENT OBJECTIVE:
|
CM-6 CONFIGURATION SETTINGS
| FAMILY: CONFIGURATION MANAGEMENT | CLASS: OPERATIONAL |
- Security Control Baseline:
| CM-6 | Configuration Settings | P1 | LOW CM-6 | MOD CM-6 (3) | HIGH CM-6 (1) (2) (3) |
| SECURITY CONTROL |
|---|
|
CM-6 CONFIGURATION SETTINGS
|
| ASSESSMENT PROCEDURE | ||
|---|---|---|
| CM-6 | CONFIGURATION SETTINGS | |
| CM-6.1 | ASSESSMENT OBJECTIVE:
| |
| SECURITY CONTROL ENHANCEMENT |
|---|
|
| CM-6(1) | CONFIGURATION SETTINGS | |
| CM-6(1).1 | ASSESSMENT OBJECTIVE:
|
| SECURITY CONTROL ENHANCEMENT |
|---|
|
| CM-6(2) | CONFIGURATION SETTINGS | |
| CM-6(2).1 | ASSESSMENT OBJECTIVE:
|
| SECURITY CONTROL ENHANCEMENT |
|---|
|
| CM-6(3) | CONFIGURATION SETTINGS | |
| CM-6(3).1 | ASSESSMENT OBJECTIVE:
|
| SECURITY CONTROL ENHANCEMENT |
|---|
|
| CM-6(4) | CONFIGURATION SETTINGS | |
| CM-6(4).1 | ASSESSMENT OBJECTIVE:
|
CM-7 LEAST FUNCTIONALITY
| FAMILY: CONFIGURATION MANAGEMENT | CLASS: OPERATIONAL |
- Security Control Baseline:
| CM-7 | Least Functionality | P1 | LOW CM-7 | MOD CM-7 (1) | HIGH CM-7 (1) (2) |
| SECURITY CONTROL |
|---|
|
CM-7 LEAST FUNCTIONALITY
|
| ASSESSMENT PROCEDURE | ||
|---|---|---|
| CM-7 | LEAST FUNCTIONALITY | |
| CM-7.1 | ASSESSMENT OBJECTIVE:
| |
| SECURITY CONTROL ENHANCEMENT |
|---|
|
| CM-7(1) | LEAST FUNCTIONALITY | |
| CM-7(1).1 | ASSESSMENT OBJECTIVE:
|
| SECURITY CONTROL ENHANCEMENT |
|---|
|
| CM-7(2) | LEAST FUNCTIONALITY | |
| CM-7(2).1 | ASSESSMENT OBJECTIVE:
|
| SECURITY CONTROL ENHANCEMENT |
|---|
|
| CM-7(3) | LEAST FUNCTIONALITY | |
| CM-7(3).1 | ASSESSMENT OBJECTIVE:
|
CM-8 INFORMATION SYSTEM COMPONENT INVENTORY
| FAMILY: CONFIGURATION MANAGEMENT | CLASS: OPERATIONAL |
- Security Control Baseline:
| CM-8 | Information System Component Inventory | P1 | LOW CM-8 | MOD CM-8 (1) (5) | HIGH CM-8 (1) (2) (3) (4) (5) |
| SECURITY CONTROL |
|---|
|
CM-8 INFORMATION SYSTEM COMPONENT INVENTORY
|
| ASSESSMENT PROCEDURE | ||
|---|---|---|
| CM-8 | INFORMATION SYSTEM COMPONENT INVENTORY | |
| CM-8.1 | ASSESSMENT OBJECTIVE:
| |
| SECURITY CONTROL ENHANCEMENT |
|---|
|
| CM-8(1) | INFORMATION SYSTEM COMPONENT INVENTORY | |
| CM-8(1).1 | ASSESSMENT OBJECTIVE:
|
| SECURITY CONTROL ENHANCEMENT |
|---|
|
| CM-8(2) | INFORMATION SYSTEM COMPONENT INVENTORY | |
| CM-8(2).1 | ASSESSMENT OBJECTIVE:
|
| SECURITY CONTROL ENHANCEMENT |
|---|
|
| CM-8(3) | INFORMATION SYSTEM COMPONENT INVENTORY | |
| CM-8(3).1 | ASSESSMENT OBJECTIVE:
|
| SECURITY CONTROL ENHANCEMENT |
|---|
|
| CM-8(4) | INFORMATION SYSTEM COMPONENT INVENTORY | |
| CM-8(4).1 | ASSESSMENT OBJECTIVE:
|
| SECURITY CONTROL ENHANCEMENT |
|---|
|
| CM-8(5) | INFORMATION SYSTEM COMPONENT INVENTORY | |
| CM-8(5).1 | ASSESSMENT OBJECTIVE:
|
| SECURITY CONTROL ENHANCEMENT |
|---|
|
| CM-8(6) | INFORMATION SYSTEM COMPONENT INVENTORY | |
| CM-8(6).1 | ASSESSMENT OBJECTIVE:
|
CM-9 CONFIGURATION MANAGEMENT PLAN
| FAMILY: CONFIGURATION MANAGEMENT | CLASS: OPERATIONAL |
- Security Control Baseline:
| CM-9 | Configuration Management Plan | P1 | LOW Not Selected | MOD CM-9 | HIGH CM-9 |
| SECURITY CONTROL |
|---|
|
CM-9 CONFIGURATION MANAGEMENT PLAN
|
| ASSESSMENT PROCEDURE | ||
|---|---|---|
| CM-9 | CONFIGURATION MANAGEMENT PLAN | |
| CM-9.1 | ASSESSMENT OBJECTIVE:
| |
| SECURITY CONTROL ENHANCEMENT |
|---|
|
| CM-9(1) | CONFIGURATION MANAGEMENT PLAN | |
| CM-9(1).1 | ASSESSMENT OBJECTIVE:
|
del.icio.us
digg
Facebook
Newsvine
reddit
Slashdot