id: "CM-07(01)" title: "Periodic Review" family: "CM" family_name: "Configuration Management" sort_id: "cm-07.01" priority: "P1" implementation_level: "system" parent: "CM-07" enhancement: True
Review the system {{ insert: param, cm-07.01_odp.01 }} to identify unnecessary and/or nonsecure functions, ports, protocols, software, and services; and
Disable or remove {{ insert: param, cm-7.1_prm_2 }}.
Guidance
Organizations review functions, ports, protocols, and services provided by systems or system components to determine the functions and services that are candidates for elimination. Such reviews are especially important during transition periods from older technologies to newer technologies (e.g., transition from IPv4 to IPv6). These technology transitions may require implementing the older and newer technologies simultaneously during the transition period and returning to minimum essential functions, ports, protocols, and services at the earliest opportunity. Organizations can either decide the relative security of the function, port, protocol, and/or service or base the security decision on the assessment of other entities. Unsecure protocols include Bluetooth, FTP, and peer-to-peer networking.
Assessment Objective: the system is reviewed {{ insert: param, cm-07.01_odp.01 }} to identify unnecessary and/or non-secure functions, ports, protocols, software, and services:
Assessment Objective: {{ insert: param, cm-07.01_odp.02 }} deemed to be unnecessary and/or non-secure are disabled or removed;
Assessment Objective: {{ insert: param, cm-07.01_odp.03 }} deemed to be unnecessary and/or non-secure are disabled or removed;
Assessment Objective: {{ insert: param, cm-07.01_odp.04 }} deemed to be unnecessary and/or non-secure are disabled or removed;
Assessment Objective: {{ insert: param, cm-07.01_odp.05 }} deemed to be unnecessary and/or non-secure is disabled or removed;
Assessment Objective: {{ insert: param, cm-07.01_odp.06 }} deemed to be unnecessary and/or non-secure are disabled or removed.
Configuration management policy
procedures addressing least functionality in the system
configuration management plan
system design documentation
system configuration settings and associated documentation
common secure configuration checklists
documented reviews of functions, ports, protocols, and/or services
change control records
system audit records
system security plan
other relevant documents or records
Organizational personnel with responsibilities for reviewing functions, ports, protocols, and services on the system
organizational personnel with information security responsibilities
system/network administrators
system developers
Organizational processes for reviewing or disabling functions, ports, protocols, and services on the system
mechanisms implementing review and disabling of functions, ports, protocols, and/or services