Skip to content

Family 3.4 9 requirements

Configuration Management.

Known-good baselines. Disciplined change.

The big picture

Drift kills you in CMMC. Document what 'good' looks like, then enforce it — every change tracked, every deviation explained.

Theme 1

Baseline configs.

3.4.1 — 3.4.2

Establishing a known-good configuration and enforcing security settings on every system.

Theme 2

Change control.

3.4.3 — 3.4.5

Tracking changes, analysing security impact, and limiting who can make them.

Theme 3

Software and ports.

3.4.6 — 3.4.9

Least functionality, restricted services, allowlisted software, and user-installed software control.