Skip to main content

πŸ’Ό CM-2 Baseline Configuration (L)(M)(H)

  • Contextual name: πŸ’Ό CM-2 Baseline Configuration (L)(M)(H)
  • ID: /frameworks/fedramp-high-security-controls/cm/02
  • Located in: πŸ’Ό Configuration Management

Description​

a. Develop, document, and maintain under configuration control, a current baseline configuration of the system; and

b. Review and update the baseline configuration of the system:

  1. [FedRAMP Assignment: at least annually and when a significant change occurs];

  2. When required due to [FedRAMP Assignment: to include when directed by the JAB]; and

  3. When system components are installed or upgraded.

CM-2 Additional FedRAMP Requirements and Guidance:

(b) (1) Guidance: Significant change is defined in NIST Special Publication 800-37 Revision 2, Appendix F.

Similar​

  • Sections
    • /frameworks/nist-sp-800-53-r5/cm/02
  • Internal
    • ID: dec-c-aa2b018a

Similar Sections (Take Policies From)​

SectionSub SectionsInternal RulesPoliciesFlags
πŸ’Ό NIST SP 800-53 Revision 5 β†’ πŸ’Ό CM-2 Baseline Configuration713

Similar Sections (Give Policies To)​

SectionSub SectionsInternal RulesPoliciesFlags
πŸ’Ό FedRAMP Low Security Controls β†’ πŸ’Ό CM-2 Baseline Configuration (L)(M)(H)13
πŸ’Ό FedRAMP Moderate Security Controls β†’ πŸ’Ό CM-2 Baseline Configuration (L)(M)(H)314

Sub Sections​

SectionSub SectionsInternal RulesPoliciesFlags
πŸ’Ό CM-2(2) Automation Support for Accuracy and Currency (M)(H)13
πŸ’Ό CM-2(3) Retention of Previous Configurations (M)(H)11
πŸ’Ό CM-2(7) Configure Systems and Components for High-risk Areas (M)(H)

Policies (13)​

PolicyLogic CountFlags
πŸ“ AWS Account Alternate Contact Information is not current πŸ”΄πŸŸ’πŸ”΄ x1, 🟒 x3
πŸ“ AWS API Gateway API Route Authorization Type is not configured 🟒1🟒 x6
πŸ“ AWS EC2 Security Group allows public IPv4 (0.0.0.0/0) access to admin ports 🟒1🟒 x6
πŸ“ AWS EC2 Security Group allows public IPv6 (::/0) access to admin ports 🟒1🟒 x6
πŸ“ AWS EC2 Security Group allows unrestricted CIFS traffic 🟒1🟒 x6
πŸ“ AWS EC2 Security Group allows unrestricted FTP traffic 🟒1🟒 x6
πŸ“ AWS EC2 Security Group allows unrestricted RPC traffic 🟒1🟒 x6
πŸ“ AWS EC2 Security Group allows unrestricted SMTP traffic 🟒1🟒 x6
πŸ“ AWS EC2 Security Group allows unrestricted traffic to MSSQL 🟒1🟒 x6
πŸ“ AWS EC2 Security Group allows unrestricted traffic to MySQL 🟒1🟒 x6
πŸ“ AWS EC2 Security Group allows unrestricted traffic to PostgreSQL 🟒1🟒 x6
πŸ“ AWS EC2 Security Group allows unrestricted Telnet traffic 🟒1🟒 x6
πŸ“ AWS VPC Network ACL exposes admin ports to public internet ports 🟒1🟒 x6