NIST SP 800-171 Rev 2 · 3.4 Configuration Management
3.4.7 Restrict nonessential programs and services
Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services.
- SPRS weight
- 5
- 5 points deducted from 110 when not implemented.
- CMMC level
- L2
- Level 2 only; not among the 17 Level 1 practices.
- Assessment objectives
- 15
- From NIST SP 800-171A, each one a “determine if” an assessor answers.
What an assessor checks
NIST SP 800-171A breaks 3.4.7 into 15 objectives. Every one has to be met for the requirement to be met; a partial answer scores as not implemented.
- [a]Determine if essential programs are defined.
- [b]Determine if the use of nonessential programs is defined.
- [c]Determine if the use of nonessential programs is restricted, disabled, or prevented as defined.
- [d]Determine if essential functions are defined.
- [e]Determine if the use of nonessential functions is defined.
- [f]Determine if the use of nonessential functions is restricted, disabled, or prevented as defined.
- [g]Determine if essential ports are defined.
- [h]Determine if the use of nonessential ports is defined.
- [i]Determine if the use of nonessential ports is restricted, disabled, or prevented as defined.
- [j]Determine if essential protocols are defined.
- [k]Determine if the use of nonessential protocols is defined.
- [l]Determine if the use of nonessential protocols is restricted, disabled, or prevented as defined.
- [m]Determine if essential services are defined.
- [n]Determine if the use of nonessential services is defined.
- [o]Determine if the use of nonessential services is restricted, disabled, or prevented as defined.
- Examine
- [SELECT FROM: Configuration management policy; procedures addressing least functionality in the system; configuration management plan; security plan; system design documentation; system configuration settings and associated documentation; specifications for preventing software program execution; security configuration checklists; documented reviews of programs, functions, ports, protocols, and/or services; change control records; system audit logs and records; other relevant documents or records].
- Interview
- [SELECT FROM: Personnel with responsibilities for reviewing programs, functions, ports, protocols, and services on the system; personnel with information security responsibilities; system or network administrators; system developers].
- Test
- [SELECT FROM: Organizational processes for reviewing and disabling nonessential programs, functions, ports, protocols, or services; mechanisms implementing review and handling of nonessential programs, functions, ports, protocols, or services; organizational processes preventing program execution on the system; organizational processes for software program usage and restrictions; mechanisms supporting or implementing software program usage and restrictions; mechanisms preventing program execution on the system].
If it is open: POA&M eligibility
Not POA&M-eligible: above the 1-point ceiling · 5 points deducted
Worth 5 points. No requirement over 1 point may appear on a Level 2 POA&M, so this has to be closed before the assessment.
A POA&M is only permitted at a score of 88 or above, and closes in one 180-day window. Check a full gap list or compute your score.
Where 3.4.7 maps
NIST SP 800-53 Rev 5
No direct mapping.
NIST CSF 2.0
No direct mapping.
SOC 2
No direct mapping.
Query it from your own tools
This page and the MacTech CMMC MCP server render the same dataset. Ask your assistant and it will answer from the methodology, not from memory.
lookup_control 3.4.7 get_assessment_objectives 3.4.7 generate_poam_entries ["3.4.7"]
Install the MCP server, free, no account.
From MacZine