NIST SP 800-128 – Guide for Security-Focused Configuration Management of Information Systems

SmartSuite provides the system for managing controls, evidence, mappings, assessments, and reporting. Framework text may require a separate license unless explicitly provided.
Overview
NIST SP 800-128, Guide for Security-Focused Configuration Management of Information Systems, explains how to manage the configuration of systems so that they reach and keep a secure state. It introduces the term security-focused configuration management (SecCM) to distinguish the security aspects of configuration management from its broader engineering and operational uses, and it organizes SecCM into four phases: planning, identifying and implementing configurations, controlling configuration changes, and monitoring.
The guide was published by the National Institute of Standards and Technology (NIST) in August 2011, written by Arnold Johnson, Kelley Dempsey, and Ron Ross of NIST with Sarbari Gupta and Dennis Bailey of Electrosoft Services, and updated with errata on October 10, 2019. It is written for those responsible for the security of U.S. federal systems, where it supports the Configuration Management (CM) control family of NIST SP 800-53, and it is used voluntarily by any organization that needs a disciplined way to baseline, change, and verify system configurations.
Organizations implement it by writing a SecCM plan and policy, standing up a Configuration Control Board, establishing approved secure baseline configurations built from common secure configurations such as the National Checklist Program and DISA STIGs, running every change through security impact analysis and approval, and monitoring systems for unauthorized change, with the Security Content Automation Protocol (SCAP) used to automate assessment where possible.
Why it Matters
Most successful attacks exploit systems that have drifted from a secure configuration through unmanaged change, missing patches, or default settings. NIST SP 800-128 gives organizations a repeatable process for defining what secure looks like, controlling how it changes, and proving it still holds, which is the foundation of the CM control family in NIST SP 800-53 and of continuous monitoring.
Key benefits include:
- Establish secure baselines
Each system has an approved baseline configuration that represents the most secure state consistent with its operational requirements.
- Control change before it happens
Changes are identified, proposed, reviewed, analyzed for security impact, tested, and approved before implementation, so drift is prevented rather than discovered.
- Support NIST SP 800-53 and the RMF
The guide provides the process behind the CM controls and feeds the monitoring step of the Risk Management Framework.
- Automate assessment
Guidance on SCAP-validated tools lets organizations check configurations against baselines and checklists at scale.
- Reduce operational risk
Configuration discipline limits unplanned outages and unauthorized changes as well as security exposures.
How it Works
NIST SP 800-128 has three chapters and nine appendices. Chapter 1 sets out purpose, audience, and its relationship to NIST SP 800-53, NIST SP 800-37, and NIST SP 800-137. Chapter 2 covers the fundamentals: the four SecCM phases, core concepts such as baseline configuration, configuration items, common secure configurations, and security impact analysis, and SecCM roles from the senior agency information security officer to system owners, security officers, and administrators. Chapter 3 walks through the process for each phase and the use of SCAP. Appendices supply a sample SecCM plan outline, a change request form, best practices for secure configurations, process flow charts, a Configuration Control Board charter, and a security impact analysis template.
Implementation begins with planning: a SecCM policy and plan, a Configuration Control Board, tools, and metrics. Teams then identify configuration items, build and approve baseline configurations from common secure configurations, and implement them. Every subsequent change goes through request, security impact analysis, testing, approval, and recording so that the baseline stays current. Monitoring assesses systems against their baselines, detects unauthorized change, and reports results into the organization's continuous monitoring and risk management processes.
Within SmartSuite, teams keep the SecCM plan, configuration items, and approved baselines as linked records, run change requests through security impact analysis and Configuration Control Board approval with a full audit trail, and record monitoring results and exceptions against each system. Dashboards show baseline compliance, open change requests, and unresolved deviations for system owners and security officers.
Key Elements
- Four SecCM phases
Planning, identifying and implementing configurations, controlling configuration changes, and monitoring, each detailed in Chapter 3.
- SecCM plan and policy
Organization-level policy and system-level plans that define scope, roles, tools, procedures, and metrics for configuration management.
- Baseline configurations and common secure configurations
Approved settings, software loads, patch levels, and architecture for each system, built from recognized benchmarks such as the National Checklist Program and DISA STIGs.
- Configuration change control
A Configuration Control Board, change requests, testing, approval, and access restrictions for change that keep the baseline authoritative.
- Security impact analysis
Assessment of each proposed change for its effect on the security state of the system before it is approved.
- SecCM monitoring
Assessment of systems against baselines, detection of unauthorized change, and reporting into continuous monitoring.
- SCAP automation
Use of the Security Content Automation Protocol and validated tools to check configurations consistently across many systems.
Framework Scope
NIST SP 800-128 applies to the security aspects of configuration management for systems and their components, including hardware, software, firmware, and documentation, across the system life cycle. Its primary audience is U.S. federal agencies and their contractors responsible for managing and administering system security, and it is applicable to any organization that operates systems subject to NIST SP 800-53, NIST SP 800-171, or similar configuration management controls.
Framework Objectives
The guide aims to help organizations reach a secure configuration state, maintain it through disciplined change, and verify it continuously.
Provide guidelines for managing and administering the security of federal systems through configuration management.
Define security-focused configuration management as a distinct discipline within organizational configuration management.
Support implementation of the Configuration Management control family in NIST SP 800-53.
Establish approved baseline configurations and a controlled process for changing them.
Integrate configuration monitoring with organizational risk management and continuous monitoring.
Promote automation of configuration assessment using SCAP and validated tools.
Framework in Context
NIST SP 800-128 is the implementation guide for the CM control family of NIST SP 800-53 Rev. 5 and its baselines, supports the monitor step of the Risk Management Framework in NIST SP 800-37 Rev. 2, and underpins the Platform Security and Technology Infrastructure Resilience outcomes of NIST CSF 2.0. Its baseline and change control practices correspond to CIS Control 4 and the CIS Benchmarks, to the configuration management control 8.9 in ISO/IEC 27002:2022, to the change enablement and configuration management practices of ITIL 4, and to the managed configuration and change objectives of COBIT 2019.
Common Framework Mappings
NIST SP 800-128 is commonly mapped to control frameworks and service management standards that require configuration baselines and change control, so that one SecCM program can evidence each of them.
Mapped frameworks include:
NIST 800-53 Rev.5
NIST 800-53B Rev. 5
NIST 800-37 Rev.2
NIST CSF 2.0
NIST 800-171 Rev. 3
CIS Controls v8.1
ISO 27002:2022
ITIL 4
COBIT 2019
DISA STIGs
CIS Benchmarks
- ClassificationCategoryCybersecurityDomainCybersecurityFramework FamilyNIST Special Publications
- Regulatory ContextTypeGuidanceLegal InstrumentGuidanceSectorCross-SectorIndustryCross-Industry
- Region / PublisherRegionNorth AmericaRegion DetailUnited StatesPublisherNational Institute of Standards and Technology (NIST)
- VersioningVersionOriginal edition with errata update of October 10, 2019Effective DateAugust 2011Issue DateAugust 2011 (errata update October 10, 2019)
- AdoptionAdoption ModelVoluntaryImplementation ComplexityMedium
- Official ReferenceOpen Link in New TabSource
License included / downloadable: Yes
NIST SP 800-128 is a U.S. government publication available free of charge from NIST, and its SecCM phases and templates are included with the platform.
Framework text is licensed by its publisher and is included only where stated above.
How SmartSuite Supports NIST SP 800-128
SmartSuite provides the system for managing controls, evidence, mappings, assessments, and reporting.
For NIST SP 800-128, SmartSuite holds configuration items, approved baselines, and change requests as linked records, routes each change through security impact analysis and Configuration Control Board approval, and tracks monitoring results and deviations against every system.
SecCM Control Library
Hold the four phases, the NIST SP 800-53 CM controls, and each system's SecCM plan as structured records with implementation status.
Ownership, Cadence, and Accountability
Assign system owners, security officers, and Configuration Control Board members, and schedule baseline reviews and monitoring cycles.
Evidence Collection and Audit Trail
Record change requests, security impact analyses, approvals, test results, and baseline versions with timestamps and reviewers.
Baseline Testing and Verification
Log SCAP and manual assessment results against approved baselines and track deviations to closure.
Risk and Vendor Alignment
Connect configuration items and changes to the risks, vendors, and systems they affect for security impact analysis.
Configuration Compliance Reporting
Generate status views of baseline compliance, open changes, and unauthorized change findings for leadership and auditors.
Related frameworks

NIST SP 800-53 Rev. 5 provides a catalog of security and privacy controls to manage risks to information systems.

NIST SP 800-53B provides baseline security controls to help organizations select and implement safeguards for federal information systems.

NIST RMF provides a structured process to select, implement, assess, authorize, and continuously monitor cybersecurity and privacy controls.

NIST Cybersecurity Framework (CSF) v2.0 is a risk-based framework that helps organizations manage and reduce cybersecurity risks.

NIST SP 800-171 specifies security requirements to protect Controlled Unclassified Information (CUI) in nonfederal systems and organizations.

CIS Controls v8.1 provides prioritized, practical security actions to help organizations mitigate common cyber threats and strengthen defenses.
Frequently Asked Questions For NIST SP 800-128
NIST SP 800-128 is the Guide for Security-Focused Configuration Management of Information Systems, published by NIST in August 2011 and updated with errata in October 2019. It describes how to plan configuration management, establish secure baseline configurations, control changes to them, and monitor systems so that they stay in a secure state.
SecCM is the term NIST uses for the information security aspects of configuration management. General configuration management tracks and controls all changes to a system; SecCM concentrates on the settings, software, patches, and architecture that determine the system's security state and on analyzing the security impact of every change.
Planning, which produces the SecCM policy, plan, roles, and tools; identifying and implementing configurations, which establishes the approved secure baseline; controlling configuration changes, which runs each change through request, security impact analysis, testing, and approval; and monitoring, which assesses systems against their baselines and reports unauthorized change.
It is the implementation guide for the Configuration Management (CM) control family in NIST SP 800-53. Controls such as CM-2 baseline configuration, CM-3 configuration change control, CM-4 impact analyses, and CM-6 configuration settings describe what is required; NIST SP 800-128 describes how to do it and supplies templates.
NIST guidelines are expected practice for U.S. federal agencies meeting FISMA requirements, and contractors handling controlled unclassified information meet related configuration management requirements in NIST SP 800-171. For other organizations it is voluntary and is often adopted because it aligns with CIS Controls, ISO/IEC 27002, and ITIL configuration practices.
The 2019 errata update added an abstract and keywords, replaced the term information system with system throughout, updated the FISMA citation to the Federal Information Security Modernization Act of 2014, aligned role acronyms with current NIST terminology, and made other editorial corrections. The four-phase process and the appendices were unchanged.
The Security Content Automation Protocol is a set of specifications that let tools express and check configuration settings, vulnerabilities, and patches in a standard way. Chapter 3 explains how SCAP-validated tools can automate the assessment of systems against baselines and checklists, which makes SecCM monitoring practical at scale.
Manage controls, risks, evidence, and audits in one platform designed for modern governance, risk, and compliance.

