Skip to main content

💼 CM-2 BASELINE CONFIGURATION

  • ID: /frameworks/nist-sp-800-53-r4/cm/02

Description

The organization develops, documents, and maintains under configuration control, a current baseline configuration of the information system.

Similar

  • Internal
    • ID: dec-c-34e248a1

Similar Sections (Give Policies To)

SectionSub SectionsInternal RulesPoliciesFlagsCompliance
💼 NIST CSF v1.1 → 💼 DE.AE-1: A baseline of network operations and expected data flows for users and systems is established and managed1034no data
💼 NIST CSF v1.1 → 💼 PR.DS-7: The development and testing environment(s) are separate from the production environment1no data
💼 NIST CSF v1.1 → 💼 PR.IP-1: A baseline configuration of information technology/industrial control systems is created and maintained incorporating security principles (e.g. concept of least functionality)426no data

Sub Sections

SectionSub SectionsInternal RulesPoliciesFlagsCompliance
💼 CM-2 (1) REVIEWS AND UPDATESno data
💼 CM-2 (2) AUTOMATION SUPPORT FOR ACCURACY _ CURRENCYno data
💼 CM-2 (3) RETENTION OF PREVIOUS CONFIGURATIONSno data
💼 CM-2 (4) UNAUTHORIZED SOFTWAREno data
💼 CM-2 (5) AUTHORIZED SOFTWAREno data
💼 CM-2 (6) DEVELOPMENT AND TEST ENVIRONMENTSno data
💼 CM-2 (7) CONFIGURE SYSTEMS, COMPONENTS, OR DEVICES FOR HIGH-RISK AREASno data

Policies (1)

PolicyLogic CountFlagsCompliance
🛡️ AWS S3 Bucket Versioning is not enabled🟢1🟢 x6no data

Internal Rules

RulePoliciesFlags
✉️ dec-x-2a9e52551