CM-6 Configuration Settings
CM-6 is a security control in the NIST SP 800-53 catalog that requires organizations to establish and document secure settings for the hardware, software, and firmware in their information systems. In practice, it means an organization decides what secure configuration values a system should use and then applies and maintains those settings. Configuration settings are the parameters that can be changed and that affect a system's security posture.
CM-6, Configuration Settings, is the configuration management control within the NIST SP 800-53 security and privacy control catalog maintained by NIST. It generally requires organizations to establish and document mandatory secure configuration settings for the parameters that can be changed in hardware, software, or firmware components of a system and that affect the system's security. As defined in the control, configuration settings are those changeable parameters affecting security and, in later revisions, privacy posture. The specific control text, enhancements, and assignment/selection parameters vary by revision (for example, SP 800-53 Rev. 4 versus Rev. 5) and by organizational tailoring within an applicable baseline; practitioners should verify the current authoritative control text and any agency-specific tailoring rather than relying on a fixed formulation. This entry addresses the control concept only and does not cover implementation specifics, baseline assignment, or how CM-6 is inherited, assessed, or authorized within a given system's Risk Management Framework package.
Why it matters
Configuration settings are among the most frequently exploited weaknesses in information systems because a component that is functionally operational may still ship with insecure defaults, unnecessary services, or permissive parameters. CM-6 matters because it forces an organization to make deliberate decisions about what a secure state looks like for its hardware, software, and firmware, to document those decisions, and to maintain them over time rather than leaving them to chance or vendor defaults. Without an established and documented set of mandatory configuration settings, an organization has no defensible baseline against which to detect drift, evaluate exceptions, or demonstrate that its systems are configured to reduce their attack surface.
Within the Risk Management Framework, CM-6 also underpins the credibility of an authorization decision. An Authority to Operate reflects an authorizing official's acceptance of risk based in part on the assumption that systems are configured securely and stay that way; because configuration settings can be changed, that assumption must be continuously verified rather than treated as a one-time checkbox. It is a common and important mistake to equate documenting a configuration baseline with actually maintaining it, or to treat compliance with CM-6 as equivalent to being secure. The control establishes the discipline; sustained monitoring and enforcement are what give it value.
Because the specific control text, enhancements, and assignable parameters differ across revisions of NIST SP 800-53 and across agency-specific tailoring, practitioners should not rely on a fixed formulation of what CM-6 requires. The applicable baseline and any tailoring within a given system's authorization package determine how the control is implemented in practice, and readers should confirm the current authoritative control text before relying on any particular requirement.
Who it's relevant to
Inside CM-6
Common questions
Answers to the questions practitioners most commonly ask about CM-6.