CM-6 Configuration Management

Configuration Settings

High Risk Moderate Medium Cost

CM-6 requires establishing and documenting configuration settings for products employed that reflect the most restrictive mode consistent with operational requirements; implementing those settings; identifying and applying security controls; and monitoring for changes. Where CM-2 defines the baseline, CM-6 keeps settings enforced and detectable when someone weakens them.

Control Objective

Apply restrictive, documented security settings across in-scope systems and detect unauthorized configuration changes that could expose ePHI.

Implementation Guidance

  1. Select hardened setting catalogs (CIS, vendor EHR hardening, cloud CIS) tailored to clinical needs.
  2. Enforce via GPO, MDM, infrastructure-as-code, or vendor security profiles.
  3. Document required settings for identity, encryption, screen lock, USB, PowerShell, TLS, and local admins.
  4. Monitor drift with configuration assessment tools; alert on critical regressions (BitLocker off, firewall disabled).
  5. Control who can change settings; require tickets for exceptions.
  6. Re-apply settings after rebuilds and major upgrades.
  7. Include SaaS tenant security settings (MFA defaults, session timeouts) in scope.
  8. Review setting catalogs when new threats emerge.

Real-World Use Cases

How this control shows up in healthcare and HIPAA-covered environments.

BitLocker quietly disabled

A technician turns off encryption to 'speed imaging.' CM-6 monitoring flags the drift within hours and opens a ticket before the laptop leaves the building.

EHR web TLS settings regress after upgrade

Vendor upgrade re-enables weak ciphers. CM-6 post-change checklist and scans catch it under SC-8/CM-6 before patient use.

Local admin sprawl on clinic PCs

GPO removes standing local admin for clinicians; temporary elevation uses LAPS/JIT instead of permanent rights.

Best Practices

  • Automate enforcement and drift detection.
  • Most-restrictive settings that still allow care delivery.
  • Ticketed exceptions with expiry.
  • Post-upgrade configuration verification.
  • Cover cloud tenant settings, not only OS.
  • Alert on high-impact regressions immediately.

Common Gaps & Violations

  • Hardening guide exists but is not enforced.
  • No drift monitoring.
  • Permanent exceptions for convenience.
  • Settings applied once and never rechecked after patches.
  • SaaS security defaults left on 'open for ease.'

Required Documentation

  • Configuration settings standard / benchmarks used
  • Enforcement tool configs (GPO/MDM/IaC)
  • Drift monitoring reports
  • Exception register
  • Post-change verification checklists

How to Test & Validate

  1. Assess a sample of endpoints against the settings catalog.
  2. Intentionally drift a test setting; confirm detection.
  3. Review open configuration exceptions.
  4. Verify SaaS tenant settings match standard.
  5. Check post-upgrade verification records.

Audit Considerations

Show enforcement evidence (policy application + monitoring), not only a hardening PDF. Drift without detection is a common finding.

HIPAA Mapping

How this NIST control supports HIPAA Security Rule expectations.

  • 164.312(a) Access Control — lockout, unique ID, and encryption settings implement access safeguards.
  • 164.312(a)(2)(iv) Encryption — disk/session encryption settings.
  • 164.312(b) Audit Controls — audit-related configuration settings.
  • 164.308(a)(1) Risk Management — configuration hardening treats identified risks.

Compliance Tips

  • Put 'config verify' on every EHR and IdP change ticket.
  • Start drift alerts with a small set of critical settings to avoid noise.
  • Align CM-6 session lock settings with AC-11/HIPAA automatic logoff policy language.

Frequently Asked Questions

Do we need to meet every CIS Level 2 control?

Tailor to operational needs and document risk-based deviations — CM-6 requires restrictive settings consistent with operations, not blind maximalism.

How does CM-6 relate to CM-2?

CM-2 is the baseline build; CM-6 continuously enforces and monitors the security settings that realize that baseline.

Are medical devices in scope?

Where you can configure them, yes — use vendor-supported settings and document constraints.

References & Resources

  • NIST SP 800-53 Rev. 5 — CM-6
  • CIS Benchmarks, vendor hardening guides
  • Related controls: CM-2, CM-3, AC-11, SC-8

Need Help Implementing CM-6?

Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.