Skip to content

CM-7: Least Functionality

An OSCAL Control

Statement

    • a.

      Configure the system to provide only ; and

    • b.

      Prohibit or restrict the use of the following functions, ports, protocols, software, and/or services: .

      • (b) Requirement:

        The service provider shall use Security guidelines (See CM-6) to establish list of prohibited or restricted functions, ports, protocols, and/or services or establishes its own list of prohibited or restricted functions, ports, protocols, and/or services if STIGs or CIS is not available.