graphgrc

SCF - CFG-03.1 - Periodic Review

Mechanisms exist to periodically review system configurations to identify and disable unnecessary and/or non-secure functions, ports, protocols and services.

Mapped framework controls

ISO 27002

NIST 800-53

Control questions

Does the organization periodically review system configurations to identify and disable unnecessary and/or non-secure functions, ports, protocols and services?