NIST 800-171 · Configuration Management

Requirement 3.4.7

SPRS weight
SPRS weight: 5
POA&M eligibility
Not POA&M-eligible
Assessment objectives
15 assessment objectives

Official requirement text

Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services.

Assessment objectives

Assessors don’t evaluate the requirement as one sentence; they walk these objectives one by one. Each must be met for the requirement to score.

  1. 3.4.7[a]essential programs are defined.
  2. 3.4.7[b]the use of nonessential programs is defined.
  3. 3.4.7[c]the use of nonessential programs is restricted, disabled, or prevented as defined.
  4. 3.4.7[d]essential functions are defined.
  5. 3.4.7[e]the use of nonessential functions is defined.
  6. 3.4.7[f]the use of nonessential functions is restricted, disabled, or prevented as defined.
  7. 3.4.7[g]essential ports are defined.
  8. 3.4.7[h]the use of nonessential ports is defined.
  9. 3.4.7[i]the use of nonessential ports is restricted, disabled, or prevented as defined.
  10. 3.4.7[j]essential protocols are defined.
  11. 3.4.7[k]the use of nonessential protocols is defined.
  12. 3.4.7[l]the use of nonessential protocols is restricted, disabled, or prevented as defined.
  13. 3.4.7[m]essential services are defined.
  14. 3.4.7[n]the use of nonessential services is defined.
  15. 3.4.7[o]the use of nonessential services is restricted, disabled, or prevented as defined.

Inside Valontir, this requirement carries a full plain-English guide: what it asks in normal words, what good looks like in a small shop, the evidence an assessor accepts, the common gaps that cost points, and a plain reading of every assessment objective shown above. See it in a demo.