NIST 800-171 · Configuration Management
Requirement 3.4.7
- SPRS weight
- SPRS weight: 5
- POA&M eligibility
- Not POA&M-eligible
- Assessment objectives
- 15 assessment objectives
Official requirement text
Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services.
Assessment objectives
Assessors don’t evaluate the requirement as one sentence; they walk these objectives one by one. Each must be met for the requirement to score.
- 3.4.7[a]essential programs are defined.
- 3.4.7[b]the use of nonessential programs is defined.
- 3.4.7[c]the use of nonessential programs is restricted, disabled, or prevented as defined.
- 3.4.7[d]essential functions are defined.
- 3.4.7[e]the use of nonessential functions is defined.
- 3.4.7[f]the use of nonessential functions is restricted, disabled, or prevented as defined.
- 3.4.7[g]essential ports are defined.
- 3.4.7[h]the use of nonessential ports is defined.
- 3.4.7[i]the use of nonessential ports is restricted, disabled, or prevented as defined.
- 3.4.7[j]essential protocols are defined.
- 3.4.7[k]the use of nonessential protocols is defined.
- 3.4.7[l]the use of nonessential protocols is restricted, disabled, or prevented as defined.
- 3.4.7[m]essential services are defined.
- 3.4.7[n]the use of nonessential services is defined.
- 3.4.7[o]the use of nonessential services is restricted, disabled, or prevented as defined.
Inside Valontir, this requirement carries a full plain-English guide: what it asks in normal words, what good looks like in a small shop, the evidence an assessor accepts, the common gaps that cost points, and a plain reading of every assessment objective shown above. See it in a demo.