Skip to content
Pass My CMMC
Practices Start Here Prep Timeline Glossary Free Tools About

Configuration Management

CM.L2-3.4.1
Baseline Configs and System Inventory: CM.L2-3.4.1 Guide
Document and maintain the approved state of every system and keep an inventory of everything connected to your network
moderate
CM.L2-3.4.2
CM.L2-3.4.2: Security Configuration Enforcement
Establish and enforce security configuration settings for information technology products employed in organizational systems.
moderate
CM.L2-3.4.3
CM.L2-3.4.3: System Change Management
Track, review, and approve or disapprove changes to systems in the CUI boundary.
medium
CM.L2-3.4.4
Assessing Risk Before Making Changes: CM.L2-3.4.4 Guide
Analyze the security impact of changes to information systems before implementation.
medium
CM.L2-3.4.5
Who Can Make Changes to CUI Systems: CM.L2-3.4.5 Guide
Define, document, and enforce approval requirements for physical and logical access to systems.
medium
CM.L2-3.4.6
CM.L2-3.4.6: Least Functionality
Employ the principle of least functionality by configuring systems to run only essential services and software.
medium
CM.L2-3.4.7
CM.L2-3.4.7: Nonessential Functionality
Restrict or disable nonessential functions, ports, protocols, and services.
medium
CM.L2-3.4.8
CM.L2-3.4.8: Application Execution Policy
Apply a deny-by-exception application execution policy to restrict software to authorized applications only.
hard
CM.L2-3.4.9
CM.L2-3.4.9: User-Installed Software
Control user-installed software to prevent unauthorized applications from running on systems.
medium

Pass My CMMC

Site

All Practices Start Here CMMC Levels Explained Assessment Day Glossary About

Popular Families

Access Control (AC) Incident Response (IR) System Protection (SC) All 14 families

Newsletter

Subscribe on Substack

© 2026 Pass My CMMC. This site provides general guidance based on real assessment experience. It is not legal, compliance, or professional advice. Your organization's situation is unique. Work with qualified professionals for formal assessment preparation.