πΌ CM-7 Least Functionality
- Contextual name: πΌ CM-7 Least Functionality
- ID:
/frameworks/nist-sp-800-53-r5/cm/07
- Located in: πΌ CM Configuration Management
Descriptionβ
a. Configure the system to provide only [Assignment: organization-defined mission essential capabilities]; and b. Prohibit or restrict the use of the following functions, ports, protocols, software, and/or services: [Assignment: organization-defined prohibited or restricted functions, system ports, protocols, software, and/or services].
Similarβ
- Sections
/frameworks/aws-fsbp-v1.0.0/ec2/19
/frameworks/aws-fsbp-v1.0.0/ec2/21
/frameworks/aws-fsbp-v1.0.0/transfer-family/02
- Internal
- ID:
dec-c-cc3ad3f4
- ID:
Similar Sections (Take Policies From)β
Similar Sections (Give Policies To)β
Section | Sub Sections | Internal Rules | Policies | Flags |
---|---|---|---|---|
πΌ FedRAMP High Security Controls β πΌ CM-7 Least Functionality (L)(M)(H) | 3 | 18 | 21 | |
πΌ FedRAMP Low Security Controls β πΌ CM-7 Least Functionality (L)(M)(H) | 18 |
Sub Sectionsβ
Policies (11)β
Policy | Logic Count | Flags |
---|---|---|
π AWS EC2 Security Group allows public IPv4 (0.0.0.0/0) access to admin ports π’ | 1 | π’ x6 |
π AWS EC2 Security Group allows public IPv6 (::/0) access to admin ports π’ | 1 | π’ x6 |
π AWS EC2 Security Group allows unrestricted CIFS traffic π’ | 1 | π’ x6 |
π AWS EC2 Security Group allows unrestricted FTP traffic π’ | 1 | π’ x6 |
π AWS EC2 Security Group allows unrestricted RPC traffic π’ | 1 | π’ x6 |
π AWS EC2 Security Group allows unrestricted SMTP traffic π’ | 1 | π’ x6 |
π AWS EC2 Security Group allows unrestricted traffic to MSSQL π’ | 1 | π’ x6 |
π AWS EC2 Security Group allows unrestricted traffic to MySQL π’ | 1 | π’ x6 |
π AWS EC2 Security Group allows unrestricted traffic to PostgreSQL π’ | 1 | π’ x6 |
π AWS EC2 Security Group allows unrestricted Telnet traffic π’ | 1 | π’ x6 |
π AWS VPC Network ACL exposes admin ports to public internet ports π’ | 1 | π’ x6 |