Skip to main content
CFG

Configuration Management

58 controls

Establish and enforce secure configuration baselines that implement least privilege and least functionality for Technology Assets, Applications and Services (TAAS) to support a defensible secure configuration posture.

SCF # Control Name Weight NIST CSF Frameworks
CFG-01 Configuration Management Policy 10 — Critical Govern 30
CFG-02 Configuration Management Program 9 — Critical Govern 82
CFG-03 Least Functionality 10 — Critical Protect 85
CFG-03.1 Baseline Tailoring 9 — Critical Protect 34
CFG-03.2 Development & Test Environment Configurations 5 — Medium Protect 19
CFG-04 Secure Baseline Configurations 10 — Critical Protect 134
CFG-04.1 Account Lockout 9 — Critical Protect 61
CFG-04.2 Concurrent Session Control 6 — Medium Protect 17
CFG-04.3 Session Lock 9 — Critical Protect 45
CFG-04.4 Pattern-Hiding Displays 9 — Critical Protect 21
CFG-04.5 Session Termination 9 — Critical Protect 45
CFG-04.6 User-Initiated Logouts / Message Displays 5 — Medium Protect 7
CFG-04.7 Non-Console Administrative Access 9 — Critical Protect 13
CFG-04.8 Wireless Access Authentication & Encryption 9 — Critical Protect 52
CFG-04.9 Bluetooth & Wireless Devices 7 — High Protect 4
CFG-04.10 Infrared Communications 5 — Medium Protect 2
CFG-04.11 Microphones & Web Cameras 8 — High Protect 2
CFG-04.12 Multi-Function Devices (MFD) 8 — High Protect 3
CFG-04.13 Radio Frequency Identification (RFID) Security 3 — Low Protect 1
CFG-04.14 Contactless Access Control Systems 3 — Low Protect 1
CFG-04.15 Thin Nodes 4 — Medium Protect 6
CFG-04.16 Video Teleconference (VTC) Security 8 — High Protect 3
CFG-04.17 Voice Over Internet Protocol (VoIP) Security 8 — High Protect 7
CFG-04.18 Disable Wireless Networking 5 — Medium Protect 20
CFG-05 Configure Technology Assets, Applications and/or Services (TAAS) for High-Risk Areas 8 — High Protect 60
CFG-05.1 Physically Disable or Remove Capabilities 6 — Medium Protect 12
CFG-06 Approved Configuration Deviations 9 — Critical Protect 45
CFG-07 Baseline Configuration Reviews & Updates 8 — High Detect 71
CFG-07.1 Automated Baseline Configuration Management & Verification 7 — High Detect 49
CFG-08 Periodic Configuration Reviews 8 — High Detect 43
CFG-08.1 Respond To Unauthorized Changes 9 — Critical Respond 26
CFG-08.2 Integrity Assurance & Enforcement (IAE) 3 — Low Protect 27
CFG-09 Retention Of Previous Configurations 3 — Low Identify 24
CFG-10 Network Device Configuration File Synchronization 7 — High Protect 5
CFG-11 Software Usage Restrictions 9 — Critical Protect 33
CFG-12 Restrict Roles Permitted To Install Software 9 — Critical Protect 49
CFG-12.1 Configuration Management Role Assignment 5 — Medium Identify 13
CFG-13 Open Source Software 9 — Critical Protect 18
CFG-14 Prevent Unauthorized Software Execution 7 — High Protect 34
CFG-14.1 Explicitly Allow / Deny Applications 5 — Medium Protect 57
CFG-15 Unsupported Internet Browsers & Email Clients 7 — High Protect 7
CFG-16 Zero-Touch Provisioning (ZTP) 8 — High Protect 2
CFG-17 Production Software Repository 7 — High Protect 2
CFG-17.1 Third-Party Libraries 7 — High Protect 3
CFG-17.2 Software Repository Protections 7 — High Protect 2
CFG-17.3 Software Development Repository 7 — High Protect 2
CFG-18 Embedded Sensor Capability 7 — High Protect 3
CFG-18.1 Embedded Sensor Data Use Restrictions 8 — High Protect 5
CFG-18.2 Notice of Embedded Sensor Data Collection 6 — Medium Identify 5
CFG-18.3 Embedded Sensor Data Collection Minimization 8 — High Protect 12
CFG-18.4 Embedded Sensor Configuration Verification 4 — Medium Protect 2
CFG-19 Refresh from Trusted Sources 5 — Medium Protect 9
CFG-20 Hypervisor Access 9 — Critical Protect 2
CFG-21 Restrict Access To Security Functions 7 — High Protect 20
CFG-22 Host-Based Security Function Isolation 7 — High Protect 16
CFG-23 Control Assurance Automation (CAA) Change Control 7 — High Protect 0
CFG-24 Control Assurance Automation (CAA) Unauthorized Change Detection 7 — High Detect 0
CFG-25 Control Assurance Automation (CAA) Separation of Duties 8 — High Protect 0

The Secure Controls Framework (SCF) is maintained by SCF Council. Use of SCF content is subject to the SCF Terms & Conditions.

Manage SCF Controls in SCF Connect

Streamline your compliance program with automated control tracking, evidence management, and framework mapping.