CM-2

  • Requirement

    1. Develop, document, and maintain under configuration control, a current baseline configuration of the system; and
    2. Review and update the baseline configuration of the system:
      1. [Assignment: organization-defined frequency];
      2. When required due to [Assignment: organization-defined circumstances]; and
      3. When system components are installed or upgraded.
  • Discussion

    Baseline configurations for systems and system components include connectivity, operational, and communications aspects of systems. Baseline configurations are documented, formally reviewed, and agreed-upon specifications for systems or configuration items within those systems. Baseline configurations serve as a basis for future builds, releases, or changes to systems and include security and privacy control implementations, operational procedures, information about system components, network topology, and logical placement of components in the system architecture. Maintaining baseline configurations requires creating new baselines as organizational systems change over time. Baseline configurations of systems reflect the current enterprise architecture.

More Info

  • Title

    Baseline Configuration
  • Family

    Configuration Management
  • NIST 800-53B Baseline(s)

    • Low
    • Moderate
    • High
  • Related NIST 800-53 ID

    AC-19;AU-6;CA-9;CM-1;CM-3;CM-5;CM-6;CM-8;CM-9;CP-9;CP-10;CP-12;MA-2;PL-8;PM-5;SA-8;SA-10;SA-15;SC-18

NIST 800-53A Assessment Guidance

CMMC Training

Our CMMC Overview Course simplifies CMMC. Enroll so you can make informed decisions!