STIGhub
STIGs
RMF Controls
Compare
← All Controls
CM-6
Configuration Management
Rev 4
Configuration Settings
CCI Identifiers (18)
CCI-000363
The organization defines security configuration checklists to be used to establish and document configuration settings for the information system technology products employed.
CCI-000364
The organization establishes configuration settings for information technology products employed within the information system using organization-defined security configuration checklists.
CCI-000365
The organization documents configuration settings for information technology products employed within the information system using organization-defined security configuration checklists that reflect the most restrictive mode consistent with operational requirements.
CCI-000366
Implement the security configuration settings.
CCI-000367
Identify any deviations from the established configuration settings for organization-defined system components based on organization-defined operational requirements.
CCI-000368
Document any deviations from the established configuration settings for organization-defined system components based on organization-defined operational requirements.
CCI-000369
Approve any deviations from the established configuration settings for organization-defined system components based on organization-defined operational requirements.
CCI-001503
The organization controls changes to the configuration settings in accordance with organizational policies and procedures.
CCI-001502
The organization monitors changes to the configuration settings in accordance with organizational policies and procedures.
CCI-001588
The organization-defined security configuration checklists reflect the most restrictive mode consistent with operational requirements.
CCI-001755
Defines the system components for which any deviation from the established configuration settings are to be identified, documented, and approved.
CCI-001756
Defines the operational requirements on which the configuration settings for the organization-defined system components are to be based.
CCI-003941
Establish and document configuration settings for components employed within the system that reflect the most restrictive mode consistent with operational requirements using organization-defined common secure configurations.
CCI-003942
Defines the common secure configurations for establishing and documenting configuration settings within the system, that reflect the most restrictive mode consistent with operational requirements.
CCI-003943
Monitor changes to the configuration settings in accordance with organizational policies.
CCI-003944
Monitor changes to the configuration settings in accordance with organizational procedures.
CCI-003945
Control changes to the configuration settings in accordance with organizational policies.
CCI-003946
Control changes to the configuration settings in accordance with organizational procedures.
Linked STIG Checks (200)
Across 18 STIGs. Click to expand.
▶
A10 Networks ADC ALG Security Technical Implementation Guide
5 checks
▶
A10 Networks ADC NDM Security Technical Implementation Guide
20 checks
▶
AAA Services Security Requirements Guide
8 checks
▶
Active Directory Domain Security Technical Implementation Guide
30 checks
▶
Active Directory Forest Security Technical Implementation Guide
5 checks
▶
Adobe ColdFusion Security Technical Implementation Guide
16 checks
▶
Akamai KSD Service Impact Level 2 ALG Security Technical Implementation Guide
1 check
▶
Akamai KSD Service Impact Level 2 NDM Security Technical Implementation Guide
4 checks
▶
Amazon Linux 2023 Security Technical Implementation Guide
7 checks
▶
Anduril NixOS Security Technical Implementation Guide
9 checks
▶
Apache Server 2.4 UNIX Server Security Technical Implementation Guide
5 checks
▶
Apache Server 2.4 UNIX Site Security Technical Implementation Guide
1 check
▶
Apache Server 2.4 Windows Server Security Technical Implementation Guide
4 checks
▶
Apache Server 2.4 Windows Site Security Technical Implementation Guide
1 check
▶
Apache Tomcat Application Server 9 Security Technical Implementation Guide
8 checks
▶
Apple iOS-iPadOS 16 Security Technical Implementation Guide
45 checks
▶
Apple iOS/iPad OS 16 MDFPP 3.3 BYOAD Security Technical Implementation Guide
15 checks
▶
Apple iOS/iPadOS 15 Security Technical Implementation Guide
16 checks