CM-02 Baseline Configuration

Configuration Management

Low Moderate High

Description

The organization develops, documents, and maintains a current baseline configuration of the information system.\n

Supplemental Guidance

This control establishes a baseline configuration for the information system. The baseline configuration provides information about a particular component’s makeup (e.g., the standard software load for a workstation or notebook computer including updated patch information) and the component’s logical placement within the information system architecture. The baseline configuration also provides the organization with a well-defined and documented specification to which the information system is built and deviations, if required, are documented in support of mission needs/objectives. The baseline configuration of the information system is consistent with the Federal Enterprise Architecture. Related security controls: CM-6, CM-8.\n

Changes from Rev 4

Adds requirement to update baseline configuration document at organizationally-defined frequencies and for organizationally-defined circumstances (in addition to when changes are made) Incorporates withdrawn control CM-2(1)

Enhancements

\n

Compliance Mappings

ISO 27002:2022

8.128.258.268.38.58.9

COBIT 2019

BAI10.02BAI10.03BAI10.05DSS06.06

CIS Controls v8

10.310.410.516.74.14.104.24.34.44.54.64.74.8

NIST CSF 2.0

PR.DS-10PR.PSPR.PS-05

SOC 2 TSC

CC6.1-POF7CC6.7-POF1CC7.1CC7.1-POF1CC8.1CC8.1-POF12CC8.1-POF6

ISO 17799 (legacy)

7.1.115.1.2

COBIT 4.1 (legacy)

PO1.6PO2.1DS9.1