EHR interface server with RDP, FTP, and unused SQL browser
Attack surface includes cleartext FTP. CM-7 removes FTP, limits RDP to jump hosts, and disables unused SQL features.
CM-7 requires configuring systems to provide only essential capabilities and prohibiting or restricting the use of functions, ports, protocols, and services as defined by the organization. Clinical servers and workstations often ship with extra roles and open ports — least functionality closes what care delivery does not need.
Run ePHI-related systems with the minimum programs, services, ports, and protocols required for their clinical or business role.
How this control shows up in healthcare and HIPAA-covered environments.
Attack surface includes cleartext FTP. CM-7 removes FTP, limits RDP to jump hosts, and disables unused SQL features.
Staff installed personal remote-access apps. Least functionality + software allow-listing blocks unapproved remote tools that bypass VPN controls.
MFDs with open Telnet/HTTP admin are hardened or segmented; unused protocols disabled per vendor guidance.
Unexpected listening services on ePHI hosts are easy onsite findings. Show allow-lists and scan comparisons.
How this NIST control supports HIPAA Security Rule expectations.
Base allow-lists on vendor requirements and test in pre-prod. Document needed protocols rather than leaving everything open.
AC-6 limits user privileges; CM-7 limits system capabilities/services. Use both.
Also remove unused applications and OS roles — closed ports with risky local tools still matter.
Related controls that commonly accompany CM-7.
Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.