Cybersecurity
DETAIL

NIST SP 800-128 – Guide for Security-Focused Configuration Management of Information Systems

SmartSuite provides the system for managing controls, evidence, mappings, assessments, and reporting.
Framework text may require a separate license unless explicitly provided.

Overview

NIST SP 800-128, Guide for Security-Focused Configuration Management of Information Systems, explains how to manage the configuration of systems so that they reach and keep a secure state. It introduces the term security-focused configuration management (SecCM) to distinguish the security aspects of configuration management from its broader engineering and operational uses, and it organizes SecCM into four phases: planning, identifying and implementing configurations, controlling configuration changes, and monitoring.

The guide was published by the National Institute of Standards and Technology (NIST) in August 2011, written by Arnold Johnson, Kelley Dempsey, and Ron Ross of NIST with Sarbari Gupta and Dennis Bailey of Electrosoft Services, and updated with errata on October 10, 2019. It is written for those responsible for the security of U.S. federal systems, where it supports the Configuration Management (CM) control family of NIST SP 800-53, and it is used voluntarily by any organization that needs a disciplined way to baseline, change, and verify system configurations.

Organizations implement it by writing a SecCM plan and policy, standing up a Configuration Control Board, establishing approved secure baseline configurations built from common secure configurations such as the National Checklist Program and DISA STIGs, running every change through security impact analysis and approval, and monitoring systems for unauthorized change, with the Security Content Automation Protocol (SCAP) used to automate assessment where possible.

Why it Matters

Most successful attacks exploit systems that have drifted from a secure configuration through unmanaged change, missing patches, or default settings. NIST SP 800-128 gives organizations a repeatable process for defining what secure looks like, controlling how it changes, and proving it still holds, which is the foundation of the CM control family in NIST SP 800-53 and of continuous monitoring.

Key benefits include:

  • Establish secure baselines

Each system has an approved baseline configuration that represents the most secure state consistent with its operational requirements.

  • Control change before it happens

Changes are identified, proposed, reviewed, analyzed for security impact, tested, and approved before implementation, so drift is prevented rather than discovered.

  • Support NIST SP 800-53 and the RMF

The guide provides the process behind the CM controls and feeds the monitoring step of the Risk Management Framework.

  • Automate assessment

Guidance on SCAP-validated tools lets organizations check configurations against baselines and checklists at scale.

  • Reduce operational risk

Configuration discipline limits unplanned outages and unauthorized changes as well as security exposures.

How it Works

NIST SP 800-128 has three chapters and nine appendices. Chapter 1 sets out purpose, audience, and its relationship to NIST SP 800-53, NIST SP 800-37, and NIST SP 800-137. Chapter 2 covers the fundamentals: the four SecCM phases, core concepts such as baseline configuration, configuration items, common secure configurations, and security impact analysis, and SecCM roles from the senior agency information security officer to system owners, security officers, and administrators. Chapter 3 walks through the process for each phase and the use of SCAP. Appendices supply a sample SecCM plan outline, a change request form, best practices for secure configurations, process flow charts, a Configuration Control Board charter, and a security impact analysis template.

Implementation begins with planning: a SecCM policy and plan, a Configuration Control Board, tools, and metrics. Teams then identify configuration items, build and approve baseline configurations from common secure configurations, and implement them. Every subsequent change goes through request, security impact analysis, testing, approval, and recording so that the baseline stays current. Monitoring assesses systems against their baselines, detects unauthorized change, and reports results into the organization's continuous monitoring and risk management processes.

Within SmartSuite, teams keep the SecCM plan, configuration items, and approved baselines as linked records, run change requests through security impact analysis and Configuration Control Board approval with a full audit trail, and record monitoring results and exceptions against each system. Dashboards show baseline compliance, open change requests, and unresolved deviations for system owners and security officers.

Key Elements

  • Four SecCM phases

Planning, identifying and implementing configurations, controlling configuration changes, and monitoring, each detailed in Chapter 3.

  • SecCM plan and policy

Organization-level policy and system-level plans that define scope, roles, tools, procedures, and metrics for configuration management.

  • Baseline configurations and common secure configurations

Approved settings, software loads, patch levels, and architecture for each system, built from recognized benchmarks such as the National Checklist Program and DISA STIGs.

  • Configuration change control

A Configuration Control Board, change requests, testing, approval, and access restrictions for change that keep the baseline authoritative.

  • Security impact analysis

Assessment of each proposed change for its effect on the security state of the system before it is approved.

  • SecCM monitoring

Assessment of systems against baselines, detection of unauthorized change, and reporting into continuous monitoring.

  • SCAP automation

Use of the Security Content Automation Protocol and validated tools to check configurations consistently across many systems.

Framework Scope

NIST SP 800-128 applies to the security aspects of configuration management for systems and their components, including hardware, software, firmware, and documentation, across the system life cycle. Its primary audience is U.S. federal agencies and their contractors responsible for managing and administering system security, and it is applicable to any organization that operates systems subject to NIST SP 800-53, NIST SP 800-171, or similar configuration management controls.

Framework Objectives

The guide aims to help organizations reach a secure configuration state, maintain it through disciplined change, and verify it continuously.

Provide guidelines for managing and administering the security of federal systems through configuration management.

Define security-focused configuration management as a distinct discipline within organizational configuration management.

Support implementation of the Configuration Management control family in NIST SP 800-53.

Establish approved baseline configurations and a controlled process for changing them.

Integrate configuration monitoring with organizational risk management and continuous monitoring.

Promote automation of configuration assessment using SCAP and validated tools.

Framework in Context

NIST SP 800-128 is the implementation guide for the CM control family of NIST SP 800-53 Rev. 5 and its baselines, supports the monitor step of the Risk Management Framework in NIST SP 800-37 Rev. 2, and underpins the Platform Security and Technology Infrastructure Resilience outcomes of NIST CSF 2.0. Its baseline and change control practices correspond to CIS Control 4 and the CIS Benchmarks, to the configuration management control 8.9 in ISO/IEC 27002:2022, to the change enablement and configuration management practices of ITIL 4, and to the managed configuration and change objectives of COBIT 2019.

Common Framework Mappings

NIST SP 800-128 is commonly mapped to control frameworks and service management standards that require configuration baselines and change control, so that one SecCM program can evidence each of them.

Mapped frameworks include:

NIST 800-53 Rev.5

NIST 800-53B Rev. 5

NIST 800-37 Rev.2

NIST CSF 2.0

NIST 800-171 Rev. 3

CIS Controls v8.1

ISO 27002:2022

ITIL 4

COBIT 2019

DISA STIGs

CIS Benchmarks

At a Glance
NIST SP 800-128 – Guide for Security-Focused Configuration Management of Information Systems
  • Classification
    Category
    Cybersecurity
    Domain
    Cybersecurity
    Framework Family
    NIST Special Publications
  • Regulatory Context
    Type
    Guidance
    Legal Instrument
    Guidance
    Sector
    Cross-Sector
    Industry
    Cross-Industry
  • Region / Publisher
    Region
    North America
    Region Detail
    United States
    Publisher
    National Institute of Standards and Technology (NIST)
  • Versioning
    Version
    Original edition with errata update of October 10, 2019
    Effective Date
    August 2011
    Issue Date
    August 2011 (errata update October 10, 2019)
  • Adoption
    Adoption Model
    Voluntary
    Implementation Complexity
    Medium
  • Official Reference
License Information

License included / downloadable: Yes

NIST SP 800-128 is a U.S. government publication available free of charge from NIST, and its SecCM phases and templates are included with the platform.

Framework text is licensed by its publisher and is included only where stated above.

Official Resources
NIST SP 800-128 publication page
The NIST Computer Security Resource Center record for the guide and its October 2019 update, with status, abstract, keywords, and authors.
NIST SP 800-128 (PDF, includes updates as of October 10, 2019)
The full text of the guide, including the errata table, the four SecCM phases, and the plan, change request, CCB charter, and impact analysis templates in the appendices.
NIST SP 800-53 Rev. 5 publication page
The control catalog whose Configuration Management (CM) family NIST SP 800-128 supports.
NIST National Checklist Program
The NIST program that publishes common secure configuration checklists referenced by the guide as the basis for baseline configurations.
SMARTSUITE

How SmartSuite Supports NIST SP 800-128

SmartSuite provides the system for managing controls, evidence, mappings, assessments, and reporting.

For NIST SP 800-128, SmartSuite holds configuration items, approved baselines, and change requests as linked records, routes each change through security impact analysis and Configuration Control Board approval, and tracks monitoring results and deviations against every system.

SecCM Control Library

Hold the four phases, the NIST SP 800-53 CM controls, and each system's SecCM plan as structured records with implementation status.

Ownership, Cadence, and Accountability

Assign system owners, security officers, and Configuration Control Board members, and schedule baseline reviews and monitoring cycles.

Evidence Collection and Audit Trail

Record change requests, security impact analyses, approvals, test results, and baseline versions with timestamps and reviewers.

Baseline Testing and Verification

Log SCAP and manual assessment results against approved baselines and track deviations to closure.

Risk and Vendor Alignment

Connect configuration items and changes to the risks, vendors, and systems they affect for security impact analysis.

Configuration Compliance Reporting

Generate status views of baseline compliance, open changes, and unauthorized change findings for leadership and auditors.

Related frameworks

NIST 800-53 Rev.5

NIST SP 800-53 Rev. 5 provides a catalog of security and privacy controls to manage risks to information systems.

NIST 800-53B Rev. 5

NIST SP 800-53B provides baseline security controls to help organizations select and implement safeguards for federal information systems.

NIST 800-37 Rev.2

NIST RMF provides a structured process to select, implement, assess, authorize, and continuously monitor cybersecurity and privacy controls.

NIST CSF 2.0

NIST Cybersecurity Framework (CSF) v2.0 is a risk-based framework that helps organizations manage and reduce cybersecurity risks.

NIST 800-171 Rev. 3

NIST SP 800-171 specifies security requirements to protect Controlled Unclassified Information (CUI) in nonfederal systems and organizations.

CIS Controls v8.1

CIS Controls v8.1 provides prioritized, practical security actions to help organizations mitigate common cyber threats and strengthen defenses.

ITIL 4

ITIL 4 is a service management framework that helps organizations align IT services with business goals and improve service delivery.

ISO 27002:2022

ISO/IEC 27002:2022 provides best-practice information security controls to help organizations select, implement, and manage protections for information assets.

ONBOARDING FAQS

Frequently Asked Questions For NIST SP 800-128

What is NIST SP 800-128?

NIST SP 800-128 is the Guide for Security-Focused Configuration Management of Information Systems, published by NIST in August 2011 and updated with errata in October 2019. It describes how to plan configuration management, establish secure baseline configurations, control changes to them, and monitor systems so that they stay in a secure state.

What does security-focused configuration management (SecCM) mean?

SecCM is the term NIST uses for the information security aspects of configuration management. General configuration management tracks and controls all changes to a system; SecCM concentrates on the settings, software, patches, and architecture that determine the system's security state and on analyzing the security impact of every change.

What are the four phases of SecCM in NIST SP 800-128?

Planning, which produces the SecCM policy, plan, roles, and tools; identifying and implementing configurations, which establishes the approved secure baseline; controlling configuration changes, which runs each change through request, security impact analysis, testing, and approval; and monitoring, which assesses systems against their baselines and reports unauthorized change.

How does NIST SP 800-128 relate to NIST SP 800-53?

It is the implementation guide for the Configuration Management (CM) control family in NIST SP 800-53. Controls such as CM-2 baseline configuration, CM-3 configuration change control, CM-4 impact analyses, and CM-6 configuration settings describe what is required; NIST SP 800-128 describes how to do it and supplies templates.

Is NIST SP 800-128 mandatory?

NIST guidelines are expected practice for U.S. federal agencies meeting FISMA requirements, and contractors handling controlled unclassified information meet related configuration management requirements in NIST SP 800-171. For other organizations it is voluntary and is often adopted because it aligns with CIS Controls, ISO/IEC 27002, and ITIL configuration practices.

What changed in the October 2019 update to NIST SP 800-128?

The 2019 errata update added an abstract and keywords, replaced the term information system with system throughout, updated the FISMA citation to the Federal Information Security Modernization Act of 2014, aligned role acronyms with current NIST terminology, and made other editorial corrections. The four-phase process and the appendices were unchanged.

What is SCAP and why does NIST SP 800-128 cover it?

The Security Content Automation Protocol is a set of specifications that let tools express and check configuration settings, vulnerabilities, and patches in a standard way. Chapter 3 explains how SCAP-validated tools can automate the assessment of systems against baselines and checklists, which makes SecCM monitoring practical at scale.

Operationalize NIST SP 800-128 with Connected Workflows

Manage controls, risks, evidence, and audits in one platform designed for modern governance, risk, and compliance.