Configuration Management
That systems are built and changed to a known, secure baseline, and that unauthorized software and changes are prevented.
The 9 requirements, in plain language.
Establish and maintain baseline configurations and inventories of organizational systems (including hardware, software, firmware, and documentation) throughout the respective system development life cycles
Establish and enforce security configuration settings for information technology products employed in organizational systems
Track, review, approve or disapprove, and log changes to organizational systems
Analyze the security impact of changes prior to implementation
Define, document, approve, and enforce physical and logical access restrictions associated with changes to organizational systems
Employ the principle of least functionality by configuring organizational systems to provide only essential capabilities
Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
Apply deny-by-exception (blacklisting) policy to prevent the use of unauthorized software or deny-all, permit-by-exception (whitelisting) policy to allow the execution of authorized software
Control and monitor user-installed software
One owner across the whole family — built, run, and proven.
Enclave builds these controls into the boundary as code; Cadence keeps them enforced between assessments; Attest proves them to the C3PAO against every objective.
See all fourteen families →Not sure which families your contract puts in scope?
A readiness check maps your environment to all 110 controls and tells you exactly where you stand.