PlumbTrackLive demoGRC Risk System

← internal audit

Audit — CM-7 — Least Functionality

Framework: NIST SP 800-53 Rev.5 CM-7 · Mark each check Pass / Fail / N/A; a Fail is a finding to remediate. · open the item

0 pass · 0 finding(s) · 0 N/A · 0 of 6 checked
Examine Verify a policy/standard defines the mission-essential functions to be provided and explicitly documents the prohibited or restricted functions, ports, protocols, software, and services.
Test Scan a sample of systems (port/service enumeration) and confirm only approved ports, protocols, and services are enabled, flagging any unnecessary or unauthorized ones.
Examine Review the periodic-review records showing the organization identifies and disables unnecessary/unauthorized functions, ports, protocols, software, and services at the defined frequency (CM-7(1)).
Test Attempt to run an unauthorized/unapproved executable on a sample endpoint and confirm it is blocked, verifying application allowlisting is enforced (CM-7(5); CIS Control 2).
Interview Ask how requests to enable additional ports, protocols, services, or software are reviewed and approved before being permitted.
Examine Review the maintained allowlist (or denylist) of authorized software for currency and confirm unauthorized/unnecessary software is prevented or removed on a sample build (CM-7(4)/CM-7(5)).