NIST Special Publication 800-128, Guide for Security-Focused Configuration Management of Information Systems
NIST SP 800-128 is a guidance document from the National Institute of Standards and Technology that explains how organizations should manage the configuration of their information systems in a way that keeps security in mind. It treats information security as an integral part of an organization's overall configuration management activities. Because it is guidance rather than a mandatory standard, readers should confirm how it applies to their specific systems and compliance obligations.
NIST SP 800-128, titled 'Guide for Security-Focused Configuration Management of Information Systems,' provides guidelines for applying security-focused configuration management (SecCM) to information systems, treating information security as an integral element of an organization's overall configuration management program. It frames configuration management as a collection of activities focused on establishing and maintaining the integrity of information technology products and systems. The publication is non-binding guidance issued and maintained by NIST; it was originally published in August 2011 and later updated (an update was issued in 2019, per NIST). Practitioners should verify the current revision and update status against the authoritative CSRC text, and should note that this guide supports, but does not by itself satisfy, control-specific requirements found in baselines such as NIST SP 800-53 or other applicable frameworks.
Why it matters
Configuration management is one of the most persistent weak points in system security. Misconfigured servers, unauthorized software changes, drift from an approved baseline, and undocumented modifications routinely undermine otherwise sound security programs. NIST SP 800-128 matters because it frames information security as an integral part of an organization's configuration management activities rather than a separate, bolt-on concern, giving practitioners a structured way to establish and maintain the integrity of information technology products and systems as those systems change over time.
For organizations working under frameworks such as NIST SP 800-53, security-focused configuration management (SecCM) provides the operational discipline behind the configuration management control family. A control baseline can require a documented baseline configuration or change control process, but SP 800-128 offers the guidance on how to actually plan, implement, and monitor those activities in a security-aware way. Weak configuration management also directly affects continuous monitoring, since an authorizing official cannot trust that a system remains in its authorized state if changes are not tracked and assessed for security impact.
Who it's relevant to
Inside SP 800-128
Common questions
Answers to the questions practitioners most commonly ask about SP 800-128.