Subcontractor CMMC Tracker

Configuration Management (CM): the 9 CMMC Level 2 requirements a subcontractor self-assesses

The Configuration Management family of NIST SP 800-171 Rev 2, as CMMC Level 2 numbers it: each requirement with the value it carries in the score, our statement of the clause, and the evidence an assessor asks for.

Where frameworks a subcontractor holds may supply evidence here

The requirements

9
CMMC L2 CM.L2-3.4.1System Baselining 5 points in the score

Establish and maintain baseline configurations and inventories of systems, covering hardware, software, firmware and documentation, across the system life cycle.

What an assessor asks to see: Documented baseline configurations per system type; Asset inventory covering hardware, software and firmware; Evidence baselines are updated as systems change
Where subcontractors usually fall short: Inventory maintained but no configuration baseline defined; Baselines captured once and never maintained; Firmware and documentation excluded from scope
Source: CMMC 2.0 Level 2 (NIST SP 800-171 Rev 2)
CMMC L2 CM.L2-3.4.2Security Configuration Enforcement 5 points in the score

Define security configuration settings for the IT products used in the system and enforce those settings in operation.

What an assessor asks to see: Documented security configuration settings or hardening standards; Evidence of enforcement, for example policy objects or configuration management tooling; Compliance scan results against the defined settings
Where subcontractors usually fall short: Standards documented but drift never measured; Settings applied at build with no ongoing enforcement; Products in use with no defined hardening standard
Source: CMMC 2.0 Level 2 (NIST SP 800-171 Rev 2)
CMMC L2 CM.L2-3.4.3System Change Management 1 point in the score

Track changes to systems, review them, approve or reject them, and log the decision together with the change.

What an assessor asks to see: Change records showing request, review, decision and implementation; Change approval authority definition; Evidence unapproved changes are detected
Where subcontractors usually fall short: Emergency changes bypass the process with no retrospective record; Approvals recorded without evidence of review; Infrastructure changes tracked but application changes not
Source: CMMC 2.0 Level 2 (NIST SP 800-171 Rev 2)
CMMC L2 CM.L2-3.4.4Security Impact Analysis 1 point in the score

Analyze the security impact of a proposed change before it is implemented.

What an assessor asks to see: Security impact analysis recorded within change records; Criteria defining when deeper analysis is required; Evidence analysis occurs prior to implementation
Where subcontractors usually fall short: Impact analysis performed after deployment; Analysis reduced to a checkbox with no substance; Changes deemed routine exempted without criteria
Source: CMMC 2.0 Level 2 (NIST SP 800-171 Rev 2)
CMMC L2 CM.L2-3.4.5Access Restrictions for Change 5 points in the score

Define, document, approve and enforce the physical and logical access restrictions that apply to making changes to systems.

What an assessor asks to see: Documented and approved change access restrictions; Access control configuration limiting who can implement changes; Records showing enforcement, including physical restrictions where relevant
Where subcontractors usually fall short: Logical restrictions defined but physical access unaddressed; Restrictions documented without technical enforcement; Developers able to deploy directly to production
Source: CMMC 2.0 Level 2 (NIST SP 800-171 Rev 2)
CMMC L2 CM.L2-3.4.6Least Functionality 5 points in the score

Configure systems to provide only the capabilities that are essential, applying the principle of least functionality.

What an assessor asks to see: Documented determination of essential capabilities per system type; Configuration evidence showing nonessential capabilities removed; Periodic review of enabled capabilities
Where subcontractors usually fall short: Default installations left intact; Essential capability never actually defined; Review performed without removing anything
Source: CMMC 2.0 Level 2 (NIST SP 800-171 Rev 2)
CMMC L2 CM.L2-3.4.7Nonessential Functionality 5 points in the score

Prevent nonessential programs, functions, ports, protocols and services from being used, by restricting or disabling each one identified as unnecessary.

What an assessor asks to see: List of prohibited or restricted programs, ports, protocols and services; Configuration and scan evidence showing they are disabled or blocked; Exception records with justification
Where subcontractors usually fall short: Ports and services addressed but programs and functions ignored; Blocking at perimeter only while hosts remain open; Exceptions granted permanently without review
Source: CMMC 2.0 Level 2 (NIST SP 800-171 Rev 2)
CMMC L2 CM.L2-3.4.8Application Execution Policy 5 points in the score

Operate a software execution policy, either deny by exception blocking of unauthorized software or permit by exception allowing only authorized software.

What an assessor asks to see: Documented decision on which policy approach is used; Application control configuration implementing that policy; Maintained allow or deny list and its review records
Where subcontractors usually fall short: Policy chosen but deployed in audit mode only; Lists never maintained after initial deployment; Coverage limited to a subset of endpoints
Source: CMMC 2.0 Level 2 (NIST SP 800-171 Rev 2)
CMMC L2 CM.L2-3.4.9User-Installed Software 1 point in the score

Control which software users are able to install, and monitor what has in fact been installed on organizational systems.

What an assessor asks to see: Policy governing user installed software; Technical control restricting installation rights; Monitoring output identifying user installed software
Where subcontractors usually fall short: Users hold local administrator rights so installation is unrestricted; Control present but no monitoring of what was installed; Browser extensions and portable applications out of scope
Source: CMMC 2.0 Level 2 (NIST SP 800-171 Rev 2)