STIGhubSTIGhub
STIGsRMF ControlsCompare
STIGhub— A free STIG search and compliance tool·STIGs updated 3 days ago
Powered by Pylon·Privacy·Terms·© 2026 Beacon Cloud Solutions, Inc.
← All Controls

CM-2

Configuration ManagementRev 5organization

Baseline Configuration

Baselines:LowModerateHigh

Control Statement

a. Develop, document, and maintain under configuration control, a current baseline configuration of the system; and b. Review and update the baseline configuration of the system: 1. [Assignment: frequency]; 2. When required due to [Assignment: circumstances] ; and 3. When system components are installed or upgraded.

Supplemental Guidance

Baseline configurations for systems and system components include connectivity, operational, and communications aspects of systems. Baseline configurations are documented, formally reviewed, and agreed-upon specifications for systems or configuration items within those systems. Baseline configurations serve as a basis for future builds, releases, or changes to systems and include security and privacy control implementations, operational procedures, information about system components, network topology, and logical placement of components in the system architecture. Maintaining baseline configurations requires creating new baselines as organizational systems change over time. Baseline configurations of systems reflect the current enterprise architecture.

Related Controls (19)

AC-19AU-6CA-9CM-1CM-3CM-5CM-6CM-8CM-9CP-9CP-10CP-12MA-2PL-8PM-5SA-8SA-10SA-15SC-18

CCI Identifiers (9)

CCI-001585Defines the circumstances that require reviews and updates to the baseline configuration of the system.CCI-000294The organization documents a baseline configuration of the information system.CCI-000295Maintain, under configuration control, a current baseline configuration of the system.CCI-000293The organization develops a current baseline configuration of the information system.CCI-000296Review and update the baseline configuration of the system on an organization-defined frequency.CCI-000297Review and update the baseline configuration of the system when required due to organization-defined circumstances.CCI-001497Defines a frequency for the review and update to the baseline configuration of the system.CCI-003909Develop and document, under configuration control, a current baseline configuration of the system.

Linked STIG Checks (7)

Across 3 STIGs. Click to expand.

CCI-003910
Review and update the baseline configuration of the system when system components are installed or upgraded.