Skip to main content

πŸ’Ό CM-7(1) Periodic Review (M)(H)

  • Contextual name: πŸ’Ό CM-7(1) Periodic Review (M)(H)
  • ID: /frameworks/fedramp-high-security-controls/cm/07/01
  • Located in: πŸ’Ό CM-7 Least Functionality (L)(M)(H)

Description​

(a) Review the system [FedRAMP Assignment: at least annually] to identify unnecessary and/or nonsecure functions, ports, protocols, software, and services; and

(b) Disable or remove [Assignment: organization-defined functions, ports, protocols, software, and services within the system deemed to be unnecessary and/or nonsecure].

Similar​

  • Sections
    • /frameworks/nist-sp-800-53-r5/cm/07/01
  • Internal
    • ID: dec-c-3a09261c

Similar Sections (Take Policies From)​

SectionSub SectionsInternal RulesPoliciesFlags
πŸ’Ό NIST SP 800-53 Revision 5 β†’ πŸ’Ό CM-7(1) Least Functionality _ Periodic Review

Similar Sections (Give Policies To)​

SectionSub SectionsInternal RulesPoliciesFlags
πŸ’Ό FedRAMP Moderate Security Controls β†’ πŸ’Ό CM-7(1) Periodic Review (M)(H)11

Sub Sections​

SectionSub SectionsInternal RulesPoliciesFlags

Policies (11)​

PolicyLogic CountFlags
πŸ“ AWS EC2 Security Group allows public IPv4 (0.0.0.0/0) access to admin ports 🟒1🟒 x6
πŸ“ AWS EC2 Security Group allows public IPv6 (::/0) access to admin ports 🟒1🟒 x6
πŸ“ AWS EC2 Security Group allows unrestricted DNS traffic 🟒1🟒 x6
πŸ“ AWS EC2 Security Group allows unrestricted FTP traffic 🟒1🟒 x6
πŸ“ AWS EC2 Security Group allows unrestricted ICMP traffic 🟒1🟒 x6
πŸ“ AWS EC2 Security Group allows unrestricted NetBIOS traffic 🟒1🟒 x6
πŸ“ AWS EC2 Security Group allows unrestricted RPC traffic 🟒1🟒 x6
πŸ“ AWS EC2 Security Group allows unrestricted SMTP traffic 🟒1🟒 x6
πŸ“ AWS EC2 Security Group allows unrestricted traffic to MSSQL 🟒1🟒 x6
πŸ“ AWS EC2 Security Group allows unrestricted traffic to MySQL 🟒1🟒 x6
πŸ“ AWS EC2 Security Group allows unrestricted traffic to PostgreSQL 🟒1🟒 x6

Internal Rules​

RulePoliciesFlags
βœ‰οΈ dec-x-3e379c671
βœ‰οΈ dec-x-6eab9b881
βœ‰οΈ dec-x-11c3009f1
βœ‰οΈ dec-x-42a090841
βœ‰οΈ dec-x-293ab45b1
βœ‰οΈ dec-x-66358b451
βœ‰οΈ dec-x-bcae85fb2
βœ‰οΈ dec-x-ca1c0c0d1
βœ‰οΈ dec-x-f12d78aa1
βœ‰οΈ dec-z-dbeeed9f1
βœ‰οΈ dec-z-f778950c1