Skip to main content

πŸ’Ό CM-7 (1) PERIODIC REVIEW

  • Contextual name: πŸ’Ό CM-7 (1) PERIODIC REVIEW
  • ID: /frameworks/nist-sp-800-53-r4/cm/07/01
  • Located in: πŸ’Ό CM-7 LEAST FUNCTIONALITY

Description​

The organization: CM-7 (1)(a) Reviews the information system [Assignment: organization-defined frequency] to identify unnecessary and/or nonsecure functions, ports, protocols, and services; and CM-7 (1)(b) Disables [Assignment: organization-defined functions, ports, protocols, and services within the information system deemed to be unnecessary and/or nonsecure].

Similar​

  • Internal
    • ID: dec-c-394a8cde

Sub Sections​

SectionSub SectionsInternal RulesPoliciesFlags

Policies (4)​

PolicyLogic CountFlags
πŸ“ AWS EC2 Security Group allows public IPv4 (0.0.0.0/0) access to admin ports 🟒1🟒 x6
πŸ“ AWS EC2 Security Group allows public IPv6 (::/0) access to admin ports 🟒1🟒 x6
πŸ“ AWS S3 Bucket is not configured to block public access 🟒1🟒 x6
πŸ“ AWS S3 Bucket Policy is not set to deny HTTP requests 🟒1🟒 x6

Internal Rules​

RulePoliciesFlags
βœ‰οΈ dec-x-bcae85fb2
βœ‰οΈ dec-x-d5fbfc401
βœ‰οΈ dec-x-ec547a7c1