πΌ CM-7 LEAST FUNCTIONALITY
- Contextual name: πΌ CM-7 LEAST FUNCTIONALITY
- ID:
/frameworks/nist-sp-800-53-r4/cm/07
- Located in: πΌ CM CONFIGURATION MANAGEMENT
Descriptionβ
The organization: CM-7a. Configures the information system to provide only essential capabilities; and CM-7b. Prohibits or restricts the use of the following functions, ports, protocols, and/or services: [Assignment: organization-defined prohibited or restricted functions, ports, protocols, and/or services].
Similarβ
- Internal
- ID:
dec-c-69a5caa2
- ID:
Similar Sections (Give Policies To)β
Sub Sectionsβ
Section | Sub Sections | Internal Rules | Policies | Flags |
---|---|---|---|---|
πΌ CM-7 (1) PERIODIC REVIEW | 3 | 4 | ||
πΌ CM-7 (2) PREVENT PROGRAM EXECUTION | ||||
πΌ CM-7 (3) REGISTRATION COMPLIANCE | ||||
πΌ CM-7 (4) UNAUTHORIZED SOFTWARE _ BLACKLISTING | ||||
πΌ CM-7 (5) AUTHORIZED SOFTWARE _ WHITELISTING |
Policies (5)β
Policy | Logic Count | Flags |
---|---|---|
π AWS EC2 Security Group allows public IPv4 (0.0.0.0/0) access to admin ports π’ | 1 | π’ x6 |
π AWS EC2 Security Group allows public IPv6 (::/0) access to admin ports π’ | 1 | π’ x6 |
π AWS S3 Bucket is not configured to block public access π’ | 1 | π’ x6 |
π AWS S3 Bucket Policy is not set to deny HTTP requests π’ | 1 | π’ x6 |
π Azure Cosmos DB Account Virtual Network Filter is not enabled π’ | 1 |