Browse 1,193 controls and enhancements across 20 security and privacy families. Use the GovRAMP crosswalk to locate controls referenced by Security Snapshot, Core, and Moderate.
A shared catalog supports common-control planning; designation as a common, hybrid, or system-specific control depends on your organization’s implementation and inheritance decisions.
Sources and crosswalk scope
NIST OSCAL content 5.1.1+u4, retrieved 2026-09-18. GovRAMP Snapshot v1.4 and Core selection from Moderate v1.06 reference the December 2020 Rev. 5 text. Mappings establish exact identifier correspondence, not identical requirements, inherited implementation, or GovRAMP authorization. GovRAMP parameters and additional requirements remain authoritative for each program. Full Moderate, High, and other programs are not mapped here. Withdrawn controls are retained for reference.
Official pinned NIST sourceSHA-256: 81cf2de45ede9aef3de7ce09d65ea9d32f662c483bbf916f6e346292b22f7763
Configuration Management · Base control
CM-6 · Configuration Settings
Control statement and discussion
NIST control statement
a. Establish and document configuration settings for components employed within the system that reflect the most restrictive mode consistent with operational requirements using [Assignment: common secure configurations];
b. Implement the configuration settings;
c. Identify, document, and approve any deviations from established configuration settings for [Assignment: system components] based on [Assignment: operational requirements] ; and
d. Monitor and control changes to the configuration settings in accordance with organizational policies and procedures.
Discussion
Configuration settings are the parameters that can be changed in the hardware, software, or firmware components of the system that affect the security and privacy posture or functionality of the system. Information technology products for which configuration settings can be defined include mainframe computers, servers, workstations, operating systems, mobile devices, input/output devices, protocols, and applications. Parameters that impact the security posture of systems include registry settings; account, file, or directory permission settings; and settings for functions, protocols, ports, services, and remote connections. Privacy parameters are parameters impacting the privacy posture of systems, including the parameters required to satisfy other privacy controls. Privacy parameters include settings for access controls, data processing preferences, and processing and retention permissions. Organizations establish organization-wide configuration settings and subsequently derive specific configuration settings for systems. The established settings become part of the configuration baseline for the system.
Common secure configurations (also known as security configuration checklists, lockdown and hardening guides, and security reference guides) provide recognized, standardized, and established benchmarks that stipulate secure configuration settings for information technology products and platforms as well as instructions for configuring those products or platforms to meet operational requirements. Common secure configurations can be developed by a variety of organizations, including information technology product developers, manufacturers, vendors, federal agencies, consortia, academia, industry, and other organizations in the public and private sectors.
Implementation of a common secure configuration may be mandated at the organization level, mission and business process level, system level, or at a higher level, including by a regulatory agency. Common secure configurations include the United States Government Configuration Baseline [USGCB](#98498928-3ca3-44b3-8b1e-f48685373087) and security technical implementation guides (STIGs), which affect the implementation of [CM-6](#cm-6) and other controls such as [AC-19](#ac-19) and [CM-7](#cm-7) . The Security Content Automation Protocol (SCAP) and the defined standards within the protocol provide an effective method to uniquely identify, track, and control configuration settings.
GovRAMP crosswalk
- GovRAMP Security Snapshot Readiness · CM-6 — Direct NIST identifier reference. GovRAMP source matrix
- GovRAMP Core Readiness — 60 Controls · CM-6 — Direct NIST identifier reference. GovRAMP source matrix
- GovRAMP Moderate Readiness · CM-6 — Direct NIST identifier reference. GovRAMP source matrix
Configuration Management · Enhancement
CM-6(1) · Automated Management, Application, and Verification
View parent controlControl statement and discussion
NIST control statement
Manage, apply, and verify configuration settings for [Assignment: system components] using [Assignment: organization-defined automated mechanisms].
Discussion
Automated tools (e.g., hardening tools, baseline configuration tools) can improve the accuracy, consistency, and availability of configuration settings information. Automation can also provide data aggregation and data correlation capabilities, alerting mechanisms, and dashboards to support risk-based decision-making within the organization.
GovRAMP crosswalk
- GovRAMP Security Snapshot Readiness · CM-6 (1) — Direct NIST identifier reference. GovRAMP source matrix
- GovRAMP Core Readiness — 60 Controls · CM-6 (1) — Direct NIST identifier reference. GovRAMP source matrix
- GovRAMP Moderate Readiness · CM-6 (1) — Direct NIST identifier reference. GovRAMP source matrix
Configuration Management · Enhancement
CM-6(2) · Respond to Unauthorized Changes
View parent controlControl statement and discussion
NIST control statement
Take the following actions in response to unauthorized changes to [Assignment: configuration settings]: [Assignment: actions].
Discussion
Responses to unauthorized changes to configuration settings include alerting designated organizational personnel, restoring established configuration settings, or—in extreme cases—halting affected system processing.
GovRAMP crosswalk
Not selected in the imported Snapshot or Core sets. This does not establish exclusion from other GovRAMP baselines.
Configuration Management · Base control
CM-7 · Least Functionality
Control statement and discussion
NIST control statement
a. Configure the system to provide only [Assignment: mission-essential capabilities] ; and
b. Prohibit or restrict the use of the following functions, ports, protocols, software, and/or services: [Assignment: organization-defined prohibited or restricted functions, system ports, protocols, software, and/or services].
Discussion
Systems provide a wide variety of functions and services. Some of the functions and services routinely provided by default may not be necessary to support essential organizational missions, functions, or operations. Additionally, it is sometimes convenient to provide multiple services from a single system component, but doing so increases risk over limiting the services provided by that single component. Where feasible, organizations limit component functionality to a single function per component. Organizations consider removing unused or unnecessary software and disabling unused or unnecessary physical and logical ports and protocols to prevent unauthorized connection of components, transfer of information, and tunneling. Organizations employ network scanning tools, intrusion detection and prevention systems, and end-point protection technologies, such as firewalls and host-based intrusion detection systems, to identify and prevent the use of prohibited functions, protocols, ports, and services. Least functionality can also be achieved as part of the fundamental design and development of the system (see [SA-8](#sa-8), [SC-2](#sc-2) , and [SC-3](#sc-3)).
GovRAMP crosswalk
- GovRAMP Moderate Readiness · CM-7 — Direct NIST identifier reference. GovRAMP source matrix
Configuration Management · Enhancement
CM-7(1) · Periodic Review
View parent controlControl statement and discussion
NIST control statement
(a) Review the system [Assignment: frequency] to identify unnecessary and/or nonsecure functions, ports, protocols, software, and services; and
(b) Disable or remove [Assignment: organization-defined functions, ports, protocols, software, and services within the system deemed to be unnecessary and/or nonsecure].
Discussion
Organizations review functions, ports, protocols, and services provided by systems or system components to determine the functions and services that are candidates for elimination. Such reviews are especially important during transition periods from older technologies to newer technologies (e.g., transition from IPv4 to IPv6). These technology transitions may require implementing the older and newer technologies simultaneously during the transition period and returning to minimum essential functions, ports, protocols, and services at the earliest opportunity. Organizations can either decide the relative security of the function, port, protocol, and/or service or base the security decision on the assessment of other entities. Unsecure protocols include Bluetooth, FTP, and peer-to-peer networking.
GovRAMP crosswalk
- GovRAMP Moderate Readiness · CM-7 (1) — Direct NIST identifier reference. GovRAMP source matrix
Configuration Management · Enhancement
CM-7(2) · Prevent Program Execution
View parent controlControl statement and discussion
NIST control statement
Prevent program execution in accordance with [Selection (one-or-more): [Assignment: policies, rules of behavior, and/or access agreements regarding software program usage and restrictions] ; rules authorizing the terms and conditions of software program usage].
Discussion
Prevention of program execution addresses organizational policies, rules of behavior, and/or access agreements that restrict software usage and the terms and conditions imposed by the developer or manufacturer, including software licensing and copyrights. Restrictions include prohibiting auto-execute features, restricting roles allowed to approve program execution, permitting or prohibiting specific software programs, or restricting the number of program instances executed at the same time.
GovRAMP crosswalk
- GovRAMP Moderate Readiness · CM-7 (2) — Direct NIST identifier reference. GovRAMP source matrix
Configuration Management · Enhancement
CM-7(3) · Registration Compliance
View parent controlControl statement and discussion
NIST control statement
Ensure compliance with [Assignment: registration requirements].
Discussion
Organizations use the registration process to manage, track, and provide oversight for systems and implemented functions, ports, protocols, and services.
GovRAMP crosswalk
Not selected in the imported Snapshot or Core sets. This does not establish exclusion from other GovRAMP baselines.
Configuration Management · Enhancement
CM-7(4) · Unauthorized Software — Deny-by-exception
View parent controlControl statement and discussion
NIST control statement
(a) Identify [Assignment: software programs];
(b) Employ an allow-all, deny-by-exception policy to prohibit the execution of unauthorized software programs on the system; and
(c) Review and update the list of unauthorized software programs [Assignment: frequency].
Discussion
Unauthorized software programs can be limited to specific versions or from a specific source. The concept of prohibiting the execution of unauthorized software may also be applied to user actions, system ports and protocols, IP addresses/ranges, websites, and MAC addresses.
GovRAMP crosswalk
Not selected in the imported Snapshot or Core sets. This does not establish exclusion from other GovRAMP baselines.
Configuration Management · Enhancement
CM-7(5) · Authorized Software — Allow-by-exception
View parent controlControl statement and discussion
NIST control statement
(a) Identify [Assignment: software programs];
(b) Employ a deny-all, permit-by-exception policy to allow the execution of authorized software programs on the system; and
(c) Review and update the list of authorized software programs [Assignment: frequency].
Discussion
Authorized software programs can be limited to specific versions or from a specific source. To facilitate a comprehensive authorized software process and increase the strength of protection for attacks that bypass application level authorized software, software programs may be decomposed into and monitored at different levels of detail. These levels include applications, application programming interfaces, application modules, scripts, system processes, system services, kernel functions, registries, drivers, and dynamic link libraries. The concept of permitting the execution of authorized software may also be applied to user actions, system ports and protocols, IP addresses/ranges, websites, and MAC addresses. Organizations consider verifying the integrity of authorized software programs using digital signatures, cryptographic checksums, or hash functions. Verification of authorized software can occur either prior to execution or at system startup. The identification of authorized URLs for websites is addressed in [CA-3(5)](#ca-3.5) and [SC-7](#sc-7).
GovRAMP crosswalk
- GovRAMP Moderate Readiness · CM-7 (5) — Direct NIST identifier reference. GovRAMP source matrix
Configuration Management · Enhancement
CM-7(6) · Confined Environments with Limited Privileges
View parent controlControl statement and discussion
NIST control statement
Require that the following user-installed software execute in a confined physical or virtual machine environment with limited privileges: [Assignment: user-installed software].
Discussion
Organizations identify software that may be of concern regarding its origin or potential for containing malicious code. For this type of software, user installations occur in confined environments of operation to limit or contain damage from malicious code that may be executed.
GovRAMP crosswalk
Not selected in the imported Snapshot or Core sets. This does not establish exclusion from other GovRAMP baselines.
Configuration Management · Enhancement
CM-7(7) · Code Execution in Protected Environments
View parent controlControl statement and discussion
NIST control statement
Allow execution of binary or machine-executable code only in confined physical or virtual machine environments and with the explicit approval of [Assignment: personnel or roles] when such code is:
(a) Obtained from sources with limited or no warranty; and/or
(b) Without the provision of source code.
Discussion
Code execution in protected environments applies to all sources of binary or machine-executable code, including commercial software and firmware and open-source software.
GovRAMP crosswalk
Not selected in the imported Snapshot or Core sets. This does not establish exclusion from other GovRAMP baselines.
Configuration Management · Enhancement
CM-7(8) · Binary or Machine Executable Code
View parent controlControl statement and discussion
NIST control statement
(a) Prohibit the use of binary or machine-executable code from sources with limited or no warranty or without the provision of source code; and
(b) Allow exceptions only for compelling mission or operational requirements and with the approval of the authorizing official.
Discussion
Binary or machine executable code applies to all sources of binary or machine-executable code, including commercial software and firmware and open-source software. Organizations assess software products without accompanying source code or from sources with limited or no warranty for potential security impacts. The assessments address the fact that software products without the provision of source code may be difficult to review, repair, or extend. In addition, there may be no owners to make such repairs on behalf of organizations. If open-source software is used, the assessments address the fact that there is no warranty, the open-source software could contain back doors or malware, and there may be no support available.
GovRAMP crosswalk
Not selected in the imported Snapshot or Core sets. This does not establish exclusion from other GovRAMP baselines.
Configuration Management · Enhancement
CM-7(9) · Prohibiting The Use of Unauthorized Hardware
View parent controlControl statement and discussion
NIST control statement
(a) Identify [Assignment: hardware components];
(b) Prohibit the use or connection of unauthorized hardware components;
(c) Review and update the list of authorized hardware components [Assignment: frequency].
Discussion
Hardware components provide the foundation for organizational systems and the platform for the execution of authorized software programs. Managing the inventory of hardware components and controlling which hardware components are permitted to be installed or connected to organizational systems is essential in order to provide adequate security.
GovRAMP crosswalk
Not selected in the imported Snapshot or Core sets. This does not establish exclusion from other GovRAMP baselines.
Configuration Management · Base control
CM-8 · System Component Inventory
Control statement and discussion
NIST control statement
a. Develop and document an inventory of system components that:
1. Accurately reflects the system;
2. Includes all components within the system;
3. Does not include duplicate accounting of components or components assigned to any other system;
4. Is at the level of granularity deemed necessary for tracking and reporting; and
5. Includes the following information to achieve system component accountability: [Assignment: information] ; and
b. Review and update the system component inventory [Assignment: frequency].
Discussion
System components are discrete, identifiable information technology assets that include hardware, software, and firmware. Organizations may choose to implement centralized system component inventories that include components from all organizational systems. In such situations, organizations ensure that the inventories include system-specific information required for component accountability. The information necessary for effective accountability of system components includes the system name, software owners, software version numbers, hardware inventory specifications, software license information, and for networked components, the machine names and network addresses across all implemented protocols (e.g., IPv4, IPv6). Inventory specifications include date of receipt, cost, model, serial number, manufacturer, supplier information, component type, and physical location.
Preventing duplicate accounting of system components addresses the lack of accountability that occurs when component ownership and system association is not known, especially in large or complex connected systems. Effective prevention of duplicate accounting of system components necessitates use of a unique identifier for each component. For software inventory, centrally managed software that is accessed via other systems is addressed as a component of the system on which it is installed and managed. Software installed on multiple organizational systems and managed at the system level is addressed for each individual system and may appear more than once in a centralized component inventory, necessitating a system association for each software instance in the centralized inventory to avoid duplicate accounting of components. Scanning systems implementing multiple network protocols (e.g., IPv4 and IPv6) can result in duplicate components being identified in different address spaces. The implementation of [CM-8(7)](#cm-8.7) can help to eliminate duplicate accounting of components.
GovRAMP crosswalk
- GovRAMP Core Readiness — 60 Controls · CM-8 — Direct NIST identifier reference. GovRAMP source matrix
- GovRAMP Moderate Readiness · CM-8 — Direct NIST identifier reference. GovRAMP source matrix
Configuration Management · Enhancement
CM-8(1) · Updates During Installation and Removal
View parent controlControl statement and discussion
NIST control statement
Update the inventory of system components as part of component installations, removals, and system updates.
Discussion
Organizations can improve the accuracy, completeness, and consistency of system component inventories if the inventories are updated as part of component installations or removals or during general system updates. If inventories are not updated at these key times, there is a greater likelihood that the information will not be appropriately captured and documented. System updates include hardware, software, and firmware components.
GovRAMP crosswalk
- GovRAMP Moderate Readiness · CM-8 (1) — Direct NIST identifier reference. GovRAMP source matrix
Configuration Management · Enhancement
CM-8(2) · Automated Maintenance
View parent controlControl statement and discussion
NIST control statement
Maintain the currency, completeness, accuracy, and availability of the inventory of system components using [Assignment: organization-defined automated mechanisms].
Discussion
Organizations maintain system inventories to the extent feasible. For example, virtual machines can be difficult to monitor because such machines are not visible to the network when not in use. In such cases, organizations maintain as up-to-date, complete, and accurate an inventory as is deemed reasonable. Automated maintenance can be achieved by the implementation of [CM-2(2)](#cm-2.2) for organizations that combine system component inventory and baseline configuration activities.
GovRAMP crosswalk
Not selected in the imported Snapshot or Core sets. This does not establish exclusion from other GovRAMP baselines.
Configuration Management · Enhancement
CM-8(3) · Automated Unauthorized Component Detection
View parent controlControl statement and discussion
NIST control statement
(a) Detect the presence of unauthorized hardware, software, and firmware components within the system using [Assignment: organization-defined automated mechanisms] [Assignment: frequency] ; and
(b) Take the following actions when unauthorized components are detected: [Selection (one-or-more): disable network access by unauthorized components; isolate unauthorized components; notify [Assignment: personnel or roles] ].
Discussion
Automated unauthorized component detection is applied in addition to the monitoring for unauthorized remote connections and mobile devices. Monitoring for unauthorized system components may be accomplished on an ongoing basis or by the periodic scanning of systems for that purpose. Automated mechanisms may also be used to prevent the connection of unauthorized components (see [CM-7(9)](#cm-7.9) ). Automated mechanisms can be implemented in systems or in separate system components. When acquiring and implementing automated mechanisms, organizations consider whether such mechanisms depend on the ability of the system component to support an agent or supplicant in order to be detected since some types of components do not have or cannot support agents (e.g., IoT devices, sensors). Isolation can be achieved , for example, by placing unauthorized system components in separate domains or subnets or quarantining such components. This type of component isolation is commonly referred to as "sandboxing."
GovRAMP crosswalk
- GovRAMP Moderate Readiness · CM-8 (3) — Direct NIST identifier reference. GovRAMP source matrix
Configuration Management · Enhancement
CM-8(4) · Accountability Information
View parent controlControl statement and discussion
NIST control statement
Include in the system component inventory information, a means for identifying by [Selection (one-or-more): name; position; role] , individuals responsible and accountable for administering those components.
Discussion
Identifying individuals who are responsible and accountable for administering system components ensures that the assigned components are properly administered and that organizations can contact those individuals if some action is required (e.g., when the component is determined to be the source of a breach, needs to be recalled or replaced, or needs to be relocated).
GovRAMP crosswalk
Not selected in the imported Snapshot or Core sets. This does not establish exclusion from other GovRAMP baselines.
Configuration Management · Enhancement
CM-8(6) · Assessed Configurations and Approved Deviations
View parent controlControl statement and discussion
NIST control statement
Include assessed component configurations and any approved deviations to current deployed configurations in the system component inventory.
Discussion
Assessed configurations and approved deviations focus on configuration settings established by organizations for system components, the specific components that have been assessed to determine compliance with the required configuration settings, and any approved deviations from established configuration settings.
GovRAMP crosswalk
Not selected in the imported Snapshot or Core sets. This does not establish exclusion from other GovRAMP baselines.
Configuration Management · Enhancement
CM-8(7) · Centralized Repository
View parent controlControl statement and discussion
NIST control statement
Provide a centralized repository for the inventory of system components.
Discussion
Organizations may implement centralized system component inventories that include components from all organizational systems. Centralized repositories of component inventories provide opportunities for efficiencies in accounting for organizational hardware, software, and firmware assets. Such repositories may also help organizations rapidly identify the location and responsible individuals of components that have been compromised, breached, or are otherwise in need of mitigation actions. Organizations ensure that the resulting centralized inventories include system-specific information required for proper component accountability.
GovRAMP crosswalk
Not selected in the imported Snapshot or Core sets. This does not establish exclusion from other GovRAMP baselines.
Configuration Management · Enhancement
CM-8(8) · Automated Location Tracking
View parent controlControl statement and discussion
NIST control statement
Support the tracking of system components by geographic location using [Assignment: automated mechanisms].
Discussion
The use of automated mechanisms to track the location of system components can increase the accuracy of component inventories. Such capability may help organizations rapidly identify the location and responsible individuals of system components that have been compromised, breached, or are otherwise in need of mitigation actions. The use of tracking mechanisms can be coordinated with senior agency officials for privacy if there are implications that affect individual privacy.
GovRAMP crosswalk
Not selected in the imported Snapshot or Core sets. This does not establish exclusion from other GovRAMP baselines.
Configuration Management · Enhancement
CM-8(9) · Assignment of Components to Systems
View parent controlControl statement and discussion
NIST control statement
(a) Assign system components to a system; and
(b) Receive an acknowledgement from [Assignment: personnel or roles] of this assignment.
Discussion
System components that are not assigned to a system may be unmanaged, lack the required protection, and become an organizational vulnerability.
GovRAMP crosswalk
Not selected in the imported Snapshot or Core sets. This does not establish exclusion from other GovRAMP baselines.
Configuration Management · Base control
CM-9 · Configuration Management Plan
Control statement and discussion
NIST control statement
Develop, document, and implement a configuration management plan for the system that:
a. Addresses roles, responsibilities, and configuration management processes and procedures;
b. Establishes a process for identifying configuration items throughout the system development life cycle and for managing the configuration of the configuration items;
c. Defines the configuration items for the system and places the configuration items under configuration management;
d. Is reviewed and approved by [Assignment: personnel or roles] ; and
e. Protects the configuration management plan from unauthorized disclosure and modification.
Discussion
Configuration management activities occur throughout the system development life cycle. As such, there are developmental configuration management activities (e.g., the control of code and software libraries) and operational configuration management activities (e.g., control of installed components and how the components are configured). Configuration management plans satisfy the requirements in configuration management policies while being tailored to individual systems. Configuration management plans define processes and procedures for how configuration management is used to support system development life cycle activities.
Configuration management plans are generated during the development and acquisition stage of the system development life cycle. The plans describe how to advance changes through change management processes; update configuration settings and baselines; maintain component inventories; control development, test, and operational environments; and develop, release, and update key documents.
Organizations can employ templates to help ensure the consistent and timely development and implementation of configuration management plans. Templates can represent a configuration management plan for the organization with subsets of the plan implemented on a system by system basis. Configuration management approval processes include the designation of key stakeholders responsible for reviewing and approving proposed changes to systems, and personnel who conduct security and privacy impact analyses prior to the implementation of changes to the systems. Configuration items are the system components, such as the hardware, software, firmware, and documentation to be configuration-managed. As systems continue through the system development life cycle, new configuration items may be identified, and some existing configuration items may no longer need to be under configuration control.
GovRAMP crosswalk
- GovRAMP Security Snapshot Readiness · CM-9 — Direct NIST identifier reference. GovRAMP source matrix
- GovRAMP Core Readiness — 60 Controls · CM-9 — Direct NIST identifier reference. GovRAMP source matrix
- GovRAMP Moderate Readiness · CM-9 — Direct NIST identifier reference. GovRAMP source matrix
Configuration Management · Enhancement
CM-9(1) · Assignment of Responsibility
View parent controlControl statement and discussion
NIST control statement
Assign responsibility for developing the configuration management process to organizational personnel that are not directly involved in system development.
Discussion
In the absence of dedicated configuration management teams assigned within organizations, system developers may be tasked with developing configuration management processes using personnel who are not directly involved in system development or system integration. This separation of duties ensures that organizations establish and maintain a sufficient degree of independence between the system development and integration processes and configuration management processes to facilitate quality control and more effective oversight.
GovRAMP crosswalk
Not selected in the imported Snapshot or Core sets. This does not establish exclusion from other GovRAMP baselines.
Configuration Management · Base control
CM-10 · Software Usage Restrictions
Control statement and discussion
NIST control statement
a. Use software and associated documentation in accordance with contract agreements and copyright laws;
b. Track the use of software and associated documentation protected by quantity licenses to control copying and distribution; and
c. Control and document the use of peer-to-peer file sharing technology to ensure that this capability is not used for the unauthorized distribution, display, performance, or reproduction of copyrighted work.
Discussion
Software license tracking can be accomplished by manual or automated methods, depending on organizational needs. Examples of contract agreements include software license agreements and non-disclosure agreements.
GovRAMP crosswalk
- GovRAMP Moderate Readiness · CM-10 — Direct NIST identifier reference. GovRAMP source matrix