Skip to main content
Category: Configuration & Endpoint Security

CM-6 Configuration Settings

Also known as: CM-6, CM-06, Configuration Settings Control
Simply put

CM-6 is a security control in the NIST SP 800-53 catalog that requires organizations to establish and document secure settings for the hardware, software, and firmware in their information systems. In practice, it means an organization decides what secure configuration values a system should use and then applies and maintains those settings. Configuration settings are the parameters that can be changed and that affect a system's security posture.

Formal definition

CM-6, Configuration Settings, is the configuration management control within the NIST SP 800-53 security and privacy control catalog maintained by NIST. It generally requires organizations to establish and document mandatory secure configuration settings for the parameters that can be changed in hardware, software, or firmware components of a system and that affect the system's security. As defined in the control, configuration settings are those changeable parameters affecting security and, in later revisions, privacy posture. The specific control text, enhancements, and assignment/selection parameters vary by revision (for example, SP 800-53 Rev. 4 versus Rev. 5) and by organizational tailoring within an applicable baseline; practitioners should verify the current authoritative control text and any agency-specific tailoring rather than relying on a fixed formulation. This entry addresses the control concept only and does not cover implementation specifics, baseline assignment, or how CM-6 is inherited, assessed, or authorized within a given system's Risk Management Framework package.

Why it matters

Configuration settings are among the most frequently exploited weaknesses in information systems because a component that is functionally operational may still ship with insecure defaults, unnecessary services, or permissive parameters. CM-6 matters because it forces an organization to make deliberate decisions about what a secure state looks like for its hardware, software, and firmware, to document those decisions, and to maintain them over time rather than leaving them to chance or vendor defaults. Without an established and documented set of mandatory configuration settings, an organization has no defensible baseline against which to detect drift, evaluate exceptions, or demonstrate that its systems are configured to reduce their attack surface.

Within the Risk Management Framework, CM-6 also underpins the credibility of an authorization decision. An Authority to Operate reflects an authorizing official's acceptance of risk based in part on the assumption that systems are configured securely and stay that way; because configuration settings can be changed, that assumption must be continuously verified rather than treated as a one-time checkbox. It is a common and important mistake to equate documenting a configuration baseline with actually maintaining it, or to treat compliance with CM-6 as equivalent to being secure. The control establishes the discipline; sustained monitoring and enforcement are what give it value.

Because the specific control text, enhancements, and assignable parameters differ across revisions of NIST SP 800-53 and across agency-specific tailoring, practitioners should not rely on a fixed formulation of what CM-6 requires. The applicable baseline and any tailoring within a given system's authorization package determine how the control is implemented in practice, and readers should confirm the current authoritative control text before relying on any particular requirement.

Who it's relevant to

Information System Security Managers and System Owners
These practitioners are typically responsible for establishing, documenting, and maintaining the mandatory configuration settings that CM-6 calls for. They need to translate the control into concrete secure settings for their systems' components and to ensure those settings are sustained over time rather than allowed to drift, particularly as they support continuous monitoring obligations tied to an authorization.
Assessors and Auditors
Those assessing a system against NIST SP 800-53 must verify that mandatory configuration settings have been established, documented, and applied consistent with the applicable revision and any organizational tailoring. They should treat assessment as distinct from authorization and confirm the current authoritative control text rather than assuming a fixed formulation of the requirement.
Authorizing Officials
Because an Authority to Operate rests in part on the assumption that systems are securely configured and stay that way, authorizing officials rely on CM-6 as evidence supporting their risk acceptance. They should recognize that documented configuration settings are only meaningful if maintained and monitored, and that an ATO is time-bound and subject to continuous monitoring rather than permanent.
Government Contractors Handling Federal Systems or CUI
Contractors operating systems on behalf of federal agencies, or handling Controlled Unclassified Information, may be required to implement CM-6 as part of an applicable baseline. The specific requirement depends on the governing agreement, the relevant revision of SP 800-53, and any agency-specific tailoring, which contractors should verify against the applicable authoritative sources rather than assuming a uniform obligation.

Inside CM-6

Configuration Settings
CM-6 addresses the establishment and documentation of configuration settings for components within an information system. These settings generally reflect the most restrictive mode consistent with operational requirements, and represent the parameters that govern the security posture and functionality of hardware, software, and firmware.
Common Secure Configurations / Baselines
The control generally directs organizations to use established secure configuration checklists or benchmarks where available. Practitioners should verify the specific authoritative sources applicable to their environment, as referenced baselines vary by platform and by agency tailoring.
Implementation of Settings
CM-6 covers the requirement to implement the documented configuration settings across applicable system components, moving beyond documentation to enforced application of those settings.
Identification and Documentation of Deviations
The control generally requires that any deviations from established configuration settings be identified, documented, and approved in accordance with organizationally defined operational requirements, rather than left unmanaged.
Monitoring and Control of Changes
CM-6 is closely tied to ongoing monitoring and control of configuration settings so that unauthorized or unintended changes are detected and addressed, supporting continuous monitoring rather than a one-time configuration event.
Relationship to the CM Family and Source Publication
CM-6 is a control within the Configuration Management (CM) family of NIST SP 800-53, maintained by NIST. It operates alongside related controls such as baseline configuration and least functionality controls. Readers should confirm the exact control text, enhancements, and numbering against the applicable revision of the source publication.

Common questions

Answers to the questions practitioners most commonly ask about CM-6.

Does implementing CM-6 mean our systems are secure?
No. CM-6 establishes, documents, and enforces configuration settings, but implementing a control is not the same as achieving security. CM-6 is one control that contributes to a system's overall security posture; it addresses the establishment and enforcement of configuration parameters, not the totality of threats a system faces. Compliance with CM-6, or with any single control, should not be equated with the system being secure. Effective security generally depends on the correct implementation of the broader control set, ongoing continuous monitoring, and sound operational practices. You should verify how CM-6 interacts with related controls in your applicable baseline against the current authoritative NIST SP 800-53 text and your agency tailoring.
Once we set our configuration settings under CM-6, are we done?
No. Configuration settings are not a one-time task. CM-6 generally requires that established settings be documented, implemented, and enforced on an ongoing basis, and configurations tend to drift over time as software is updated, patches are applied, and personnel make changes. Maintaining CM-6 typically involves periodically verifying that actual settings match the approved baseline and remediating deviations. This maintenance aligns with the continuous monitoring expectations that underpin authorization decisions. Confirm the specific frequency and enforcement mechanisms required by your applicable baseline and organizational tailoring.
What sources can we use to establish the configuration settings CM-6 calls for?
CM-6 generally calls for organizations to establish and document configuration settings that reflect the most restrictive mode consistent with operational requirements. In many implementations organizations draw on established, publicly available configuration guidance and agency-specific hardening baselines to define those settings. The specific sources and any mandated baselines depend on your system's categorization, the applicable control baseline, and your organization's or agency's tailoring decisions. Because acceptable sources and mandated baselines vary by environment and change over time, confirm the current requirements against the authoritative guidance that applies to your system.
How should we handle deviations from the approved configuration baseline?
CM-6 generally contemplates that organizations identify, document, and approve any deviations from established configuration settings. In most implementations this means deviations are reviewed through the organization's configuration change process, documented with a rationale, and approved by the appropriate authority before or as part of being enforced. The exact approval workflow, documentation format, and roles involved depend on your organization's configuration management processes and any related controls in your baseline. Verify the specific deviation-handling requirements against your applicable guidance and organizational procedures.
How does CM-6 relate to automated configuration monitoring tools?
CM-6 focuses on establishing, documenting, implementing, and enforcing configuration settings; automation can support these activities but the control itself is stated in terms of outcomes rather than a specific tool. In many implementations organizations use automated mechanisms to manage, apply, and verify configuration settings, and there are related control enhancements and configuration management controls that address automation more directly. Whether automation is required, and to what degree, depends on your applicable baseline and tailoring. Confirm which enhancements apply to your system against the current authoritative text.
How does CM-6 fit with the documentation an assessor will review?
For CM-6, assessors generally look for evidence that configuration settings have been established, documented, implemented, and enforced, and that deviations are managed appropriately. In practice this may include documented baseline configuration settings, records showing settings are applied to the system, and evidence of ongoing verification. The precise evidence expected depends on the assessment approach, the applicable baseline, and agency-specific interpretations. Keep in mind that an assessment demonstrating CM-6 is satisfied is distinct from the authorization decision an authorizing official makes; confirm evidence expectations against the applicable assessment guidance for your system.

Common misconceptions

Applying a secure configuration baseline once satisfies CM-6.
CM-6 is not a one-time activity. It generally involves ongoing monitoring and control of configuration settings, as settings can drift or be changed after initial implementation. Sustained compliance depends on continuous monitoring rather than a single point-in-time configuration.
Any deviation from the documented configuration settings is prohibited.
Deviations are not inherently forbidden. CM-6 generally allows for deviations that are identified, documented, and approved consistent with operational requirements. The control emphasizes managing and authorizing exceptions rather than eliminating them entirely.
Implementing configuration settings under CM-6 means the system is secure.
Compliance with CM-6 is not equivalent to security. Applying documented configuration settings addresses one control among many; it does not by itself guarantee a secure system and must be considered alongside the broader control set and the system's overall risk posture.

Best practices

Document configuration settings for applicable system components and establish them in the most restrictive mode consistent with operational requirements, confirming the specific baselines and checklists appropriate to your platform and agency tailoring.
Implement the documented settings across all applicable components, and verify that the settings are actually enforced rather than only recorded on paper.
Establish a formal process to identify, document, and obtain approval for any deviations from the established configuration settings so that exceptions remain managed and traceable.
Integrate CM-6 into continuous monitoring so that unauthorized or unintended configuration changes are detected and remediated over time, rather than treating configuration as a one-time task.
Coordinate CM-6 with related Configuration Management family controls so that baseline configuration, change control, and configuration settings work together consistently.
Verify the exact control language, enhancements, and numbering against the applicable revision of NIST SP 800-53 and any agency-specific tailoring before relying on a particular interpretation.