graphgrc

SCF - CFG-03 - Least Functionality

Mechanisms exist to configure systems to provide only essential capabilities by specifically prohibiting or restricting the use of ports, protocols, and/or services.

Mapped framework controls

ISO 27002

NIST 800-53

Control questions

Does the organization configure systems to provide only essential capabilities by specifically prohibiting or restricting the use of ports, protocols, and/or services?