unified
UC-CONFIG-01 — Harden systems to approved secure configuration baselines
Establish, document, and maintain current baseline configurations and mandatory secure settings for all system components, including network security controls, aligned to accepted industry hardening standards. Configure systems for least functionality by disabling or restricting unnecessary ports, protocols, services, and functions. Monitor deployed configurations for deviations from baseline and for changes that introduce vulnerabilities, remediating drift as findings, and reassess baselines periodically and upon significant change.
Record JSON · Open in map · Data retrieval guide
Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.
Attributes
- domain
- Secure Configuration & Change Management
- type
- preventive
- category
- technical
Details
- unified_id
- UC-CONFIG-01
- title
- Harden systems to approved secure configuration baselines
- statement
- Establish, document, and maintain current baseline configurations and mandatory secure settings for all system components, including network security controls, aligned to accepted industry hardening standards. Configure systems for least functionality by disabling or restricting unnecessary ports, protocols, services, and functions. Monitor deployed configurations for deviations from baseline and for changes that introduce vulnerabilities, remediating drift as findings, and reassess baselines periodically and upon significant change.
- domain
- Secure Configuration & Change Management
- control_type
- preventive
- control_category
- technical
- members
- framework
- nist-800-53
- control_id
- CM-2
- coverage
- full
- relationship
- superset_of
- framework
- nist-800-53
- control_id
- CM-6
- coverage
- full
- relationship
- superset_of
- framework
- nist-800-53
- control_id
- CM-7
- coverage
- full
- relationship
- superset_of
- framework
- nist-csf-2
- control_id
- PR.PS-01
- coverage
- full
- relationship
- superset_of
- framework
- iso-27001
- control_id
- A.8.9
- coverage
- full
- relationship
- superset_of
- framework
- soc2
- control_id
- CC7.1
- coverage
- partial
- delta
- also requires monitoring susceptibility to newly discovered vulnerabilities
- relationship
- intersects_with
- framework
- pci-dss
- control_id
- PCI-Req1
- coverage
- partial
- delta
- also mandates dedicated network security controls and periodic ruleset reviews
- relationship
- intersects_with
- framework
- pci-dss
- control_id
- PCI-Req2
- coverage
- full
- relationship
- superset_of
- guidance
Source
No record-specific source URL is provided.
Connections
- SOC 2 Trust Services Readiness tests UC-CONFIG-01 — Harden systems to approved secure configuration baselines
- UC-CONFIG-01 — Harden systems to approved secure configuration baselines maps_to PCI-Req1 — Install and maintain network security controls
- framework
- pci-dss
- control_id
- PCI-Req1
- coverage
- partial
- delta
- also mandates dedicated network security controls and periodic ruleset reviews
- relationship
- intersects_with
- source_version
- v4.0.1
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- UC-CONFIG-01 — Harden systems to approved secure configuration baselines mitigates Poor network architecture and unprotected public connections
- strength
- related
- rationale
- Hardening network security controls (e.g., firewall baselines) contributes to boundary protection, but segmentation/DMZ architecture is the operative defense.
- UC-CONFIG-01 — Harden systems to approved secure configuration baselines mitigates Internet-exposed or misconfigured systems
- strength
- primary
- rationale
- Secure baselines plus least functionality (disabling unnecessary ports/protocols/services) remove the misconfigurations and unauthorized services attackers exploit.
- ISO 27001 Stage 2 Annex A Controls Audit tests UC-CONFIG-01 — Harden systems to approved secure configuration baselines
- UC-CONFIG-01 — Harden systems to approved secure configuration baselines mitigates Exploitation of known, unpatched vulnerabilities
- strength
- related
- rationale
- Least-functionality hardening disables vulnerable services and shrinks the exploitable surface, reducing exposure to known flaws; patching is the operative control.
- UC-CONFIG-01 — Harden systems to approved secure configuration baselines mitigates Poor configuration management and insecure baseline drift
- strength
- primary
- rationale
- Establishing enforced baselines and monitoring/remediating deviations is the direct defense against insecure configuration drift.
- UC-CONFIG-01 — Harden systems to approved secure configuration baselines maps_to CC7.1 — To meet its objectives, the entity uses detection and monitoring procedures to identify (1) changes to configurations that result in the introduction of new vulnerabilities, and (2) susceptibilities to newly discovered vulnerabilities.
- framework
- soc2
- control_id
- CC7.1
- coverage
- partial
- delta
- also requires monitoring susceptibility to newly discovered vulnerabilities
- relationship
- intersects_with
- source_version
- 2017 TSC
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- SOC 2 Type II Interim Testing tests UC-CONFIG-01 — Harden systems to approved secure configuration baselines
- UC-CONFIG-01 — Harden systems to approved secure configuration baselines maps_to PR.PS-01 — Platform Security: Configuration management practices are established and applied
- framework
- nist-csf-2
- control_id
- PR.PS-01
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- 2.0
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- UC-CONFIG-01 — Harden systems to approved secure configuration baselines maps_to PCI-Req2 — Apply secure configurations to all system components
- framework
- pci-dss
- control_id
- PCI-Req2
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- v4.0.1
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- UC-CONFIG-01 — Harden systems to approved secure configuration baselines maps_to CM-7 — Least Functionality
- framework
- nist-800-53
- control_id
- CM-7
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- Rev. 5
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- UC-CONFIG-01 — Harden systems to approved secure configuration baselines maps_to CM-6 — Configuration Settings
- framework
- nist-800-53
- control_id
- CM-6
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- Rev. 5
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- UC-CONFIG-01 — Harden systems to approved secure configuration baselines maps_to CM-2 — Baseline Configuration
- framework
- nist-800-53
- control_id
- CM-2
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- Rev. 5
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- Secure Baseline & Integrity Drift Management operates UC-CONFIG-01 — Harden systems to approved secure configuration baselines
- Security Control Assessment & POA&M Remediation tests UC-CONFIG-01 — Harden systems to approved secure configuration baselines
- UC-CONFIG-01 — Harden systems to approved secure configuration baselines maps_to A.8.9 — Configuration management
- framework
- iso-27001
- control_id
- A.8.9
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- 2022
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- UC-CONFIG-01 — Harden systems to approved secure configuration baselines mitigates Cloud multi-tenancy isolation and data-scavenging exploits
- strength
- related
- rationale
- Enforcing secure configuration baselines reduces the cloud/IAM misconfigurations that break tenant isolation, though platform isolation is the operative defense.