Policy and Procedures CM-1
Configuration Management · Low baseline ✗ Not implemented
Status — program-wide
What references this control
No risks name this control in their Framework field yet.
No policies reference it yet.
Link a risk or policy to this control
Attaching adds CM-1 to the item's Framework field; the ✨ AI button suggests the best match. You can also edit the Framework field on a risk / policy directly.
Source: NIST SP 800-53 Rev.5, Configuration Management family NIST SP 800-53 Rev.5. The baseline shows the lowest SP 800-53B baseline (Low / Moderate / High) this control appears in NIST SP 800-53B.
Control guide — plain-English, per NIST SP 800-53
CM-1 (Configuration Management Policy and Procedures) is the written foundation for the whole CM family. It says that changes to a system’s setup are governed on purpose: there is a policy that names the purpose, scope, roles, and management commitment, and there are procedures that turn that policy into day-to-day steps. Someone is named to own it, and it is reviewed on a schedule. It sits in the Low baseline and carries up through Moderate.
What good looks like
- Write a configuration management policy that covers purpose, scope, roles and responsibilities, and management commitment — not just a list of settings.
- Write procedures that turn the policy into concrete steps people actually follow: how a change is requested, approved, and recorded.
- Name an owner — one person or role responsible for keeping the policy and procedures current.
- Keep it consistent with the laws, standards, and guidelines you are held to, so the policy does not contradict a rule you must meet.
- Review and update on a schedule (for example, yearly) and after major events — a reorganization, a new system, or an incident.
Framework mapping
- NIST CSF 2.0 — GV.PO-01 — Policy for managing cybersecurity risks is established and communicated
- CIS Controls v8 — Control 4 — Secure Configuration of Enterprise Assets and Software
How to move it toward Implemented
- Write a one-page CM policy for this server: what ‘configuration’ means here (packages,
/etcfiles, services, firewall rules), who may change it, and who approves. - Write a short procedure next to it — how a change is requested, tested, approved, and logged — kept to steps a person can follow.
- Name the owner and set a review cadence (for example, review every 12 months and after any rebuild), and record both in the document.
- Save the policy and procedure as a dated file on the server (for example,
/etc/cm/cm-policy.md) so it lives with the asset it governs. - Attach that policy-and-procedure document as hardening evidence on the asset, naming
CM-1in the Requirement field — that moves it from ‘To assess’ toward ‘Completed’.