BitLocker quietly disabled
A technician turns off encryption to 'speed imaging.' CM-6 monitoring flags the drift within hours and opens a ticket before the laptop leaves the building.
CM-6 requires establishing and documenting configuration settings for products employed that reflect the most restrictive mode consistent with operational requirements; implementing those settings; identifying and applying security controls; and monitoring for changes. Where CM-2 defines the baseline, CM-6 keeps settings enforced and detectable when someone weakens them.
Apply restrictive, documented security settings across in-scope systems and detect unauthorized configuration changes that could expose ePHI.
How this control shows up in healthcare and HIPAA-covered environments.
A technician turns off encryption to 'speed imaging.' CM-6 monitoring flags the drift within hours and opens a ticket before the laptop leaves the building.
Vendor upgrade re-enables weak ciphers. CM-6 post-change checklist and scans catch it under SC-8/CM-6 before patient use.
GPO removes standing local admin for clinicians; temporary elevation uses LAPS/JIT instead of permanent rights.
Show enforcement evidence (policy application + monitoring), not only a hardening PDF. Drift without detection is a common finding.
How this NIST control supports HIPAA Security Rule expectations.
Tailor to operational needs and document risk-based deviations — CM-6 requires restrictive settings consistent with operations, not blind maximalism.
CM-2 is the baseline build; CM-6 continuously enforces and monitors the security settings that realize that baseline.
Where you can configure them, yes — use vendor-supported settings and document constraints.
Related controls that commonly accompany CM-6.
Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.