CM-7 Configuration Management

Least Functionality

High Risk Moderate Low Cost

CM-7 requires configuring systems to provide only essential capabilities and prohibiting or restricting the use of functions, ports, protocols, and services as defined by the organization. Clinical servers and workstations often ship with extra roles and open ports — least functionality closes what care delivery does not need.

Control Objective

Run ePHI-related systems with the minimum programs, services, ports, and protocols required for their clinical or business role.

Implementation Guidance

  1. For each system role, list required services/ports (allow-list mindset).
  2. Disable unused Windows features, Linux packages, admin shares exposure, and legacy protocols (SMBv1, Telnet, LLMNR where feasible).
  3. Restrict workstation software via allow-listing or remove local install rights (ties to AC-6).
  4. Close unused listening ports; verify with scans (RA-5).
  5. Review after application installs — vendors often enable extra components.
  6. Apply to network devices (disable unused management services).
  7. Document required exceptions (e.g., specific biomed protocols).
  8. Re-validate quarterly on critical hosts.

Real-World Use Cases

How this control shows up in healthcare and HIPAA-covered environments.

EHR interface server with RDP, FTP, and unused SQL browser

Attack surface includes cleartext FTP. CM-7 removes FTP, limits RDP to jump hosts, and disables unused SQL features.

Clinic PCs with consumer remote tools

Staff installed personal remote-access apps. Least functionality + software allow-listing blocks unapproved remote tools that bypass VPN controls.

Printer exposing old protocols

MFDs with open Telnet/HTTP admin are hardened or segmented; unused protocols disabled per vendor guidance.

Best Practices

  • Allow-list essential functions per role.
  • Pair with vulnerability scanning to find unexpected listeners.
  • Control local software installation.
  • Re-check after vendor upgrades.
  • Segment devices that cannot be fully hardened.
  • Document biomed protocol exceptions carefully.

Common Gaps & Violations

  • Default OS roles left enabled 'just in case.'
  • Workstations that can install any software.
  • Forgotten test services listening on production.
  • No review after EHR module installs.
  • Flat network used instead of hardening + segmentation.

Required Documentation

  • Least functionality standard / role allow-lists
  • Port and service baselines per system type
  • Software allow-listing policy (if used)
  • Exception register
  • Periodic review evidence

How to Test & Validate

  1. Port-scan a critical server; compare to allow-list.
  2. Attempt to install unapproved software on a clinical PC; confirm block.
  3. Review recently installed Windows features on a sample host.
  4. Verify legacy protocols are disabled where required.
  5. Check exception list currency.

Audit Considerations

Unexpected listening services on ePHI hosts are easy onsite findings. Show allow-lists and scan comparisons.

HIPAA Mapping

How this NIST control supports HIPAA Security Rule expectations.

  • 164.308(a)(1) Risk Management — reducing unnecessary services treats attack-surface risks.
  • 164.312(a)(1) Access Control — fewer network services means fewer unauthorized access paths.
  • 164.308(a)(5)(ii)(B) Malicious Software — fewer installable apps/services lowers malware footholds.
  • 164.312(e) Transmission Security — disabling cleartext legacy protocols supports transmission protection.

Compliance Tips

  • Start CM-7 on internet-facing and EHR-adjacent servers first.
  • Combine allow-listing with user education so clinicians request tools through IT.
  • Keep a 'required ports' one-pager per clinical application for firewall teams.

Frequently Asked Questions

Will least functionality break clinical apps?

Base allow-lists on vendor requirements and test in pre-prod. Document needed protocols rather than leaving everything open.

How does CM-7 relate to AC-6?

AC-6 limits user privileges; CM-7 limits system capabilities/services. Use both.

Are ports alone enough?

Also remove unused applications and OS roles — closed ports with risky local tools still matter.

References & Resources

  • NIST SP 800-53 Rev. 5 — CM-7
  • Related controls: CM-2, CM-6, AC-6, RA-5, SC-7

Need Help Implementing CM-7?

Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.