Asset & Configuration Management

Baselines. Engineered.

CM.L2-3.4.2 requires establishing and enforcing security configuration settings for every IT product in scope. The Configuration Baselines module documents your approved settings per asset category, tracks deviations with justification records, and links configuration changes to your change control process.

CM.L2 3.4.2 and 3.4.3 satisfied
Per category Baselines documented
Deviations Tracked with justification
Capability

Baseline Documentation by Asset Category

Baselines are created per asset category (Windows workstations, Windows servers, network switches, Linux servers, firewalls, and so on). Each baseline captures the security settings required for that category: password policy parameters, screen lock timeout, audit logging configuration, enabled or disabled services, firewall rules, and encryption settings. The applicable reference standard (CIS Benchmark, STIG, or organizational policy) is cited for each setting.

Each baseline is version-controlled. When the approved settings change (a new password policy is adopted, a service is added or removed), the baseline is updated with a new version, the change is documented, and the prior version is preserved. That version history demonstrates baselines are actively maintained rather than set once and forgotten.

Dashboard Requirements Evidence POA&M Reports
1TEN Configuration Baselines showing per-category security settings, reference standards, and deviation tracking
Capability

Deviation Tracking and Change Control

When a system's configuration deviates from the approved baseline (a service is enabled that is not in the standard, a setting is changed outside the change control process), that deviation is logged with a justification, an approver, and a remediation target date. Unapproved deviations are flagged for immediate attention. The deviation record demonstrates the baseline has teeth: the organization knows when systems drift from standard and responds to it.

Configuration changes that go through change control are linked to the relevant baseline. Assessors examining CM.L2-3.4.3 (change tracking and approval) can see both the documented baseline and the record of approved changes against it, producing a complete configuration management picture rather than two artifacts that do not connect.

Inside the Module

What You See Inside

Per-category baselines
Security settings, reference standard, and version history captured for each asset category.
Setting-level detail
Password policy, screen lock, audit logging, services, firewall, and encryption documented per baseline.
Reference standard cited
CIS Benchmark, STIG, or organizational policy cited for each setting.
Version controlled
Each baseline update creates a new version with prior versions preserved.
Deviation tracking
Records with justification, approver, and remediation target date; unapproved drift is flagged.
Change control and asset linkage
Approved changes link to the baseline version they affect, and baselines link to the assets they govern.
The problem this solves

CM.L2-3.4.2 is one of the most commonly misunderstood CM practices. Organizations implement security configurations (they set password policies, configure firewalls, enable audit logging) but do not document what the approved settings are or track whether systems remain in compliance with them. When an assessor asks to see your baseline configuration for Windows workstations, the answer needs to be a documented standard, not a verbal description of what is currently configured. No more undocumented settings the assessor cannot verify, no more systems drifting from standard with no record, no more change records that do not trace back to the baseline they affected.

Reference

Common Baseline Categories

Windows Workstations
Password policy, screen lock, BitLocker encryption, audit policy, Windows Defender, local admin restrictions, SMB settings.
Windows Servers
Password policy, audit policy, RDP configuration, service restrictions, Windows Firewall, patch baseline.
Linux Servers
SSH configuration, sudoers policy, audit daemon settings, firewall rules, disabled services, file permission standards.
Network Switches
Management access controls, unused port shutdown, VLAN configuration, logging settings, firmware version baseline.
Firewalls
Inbound and outbound rule standard, management interface restrictions, logging configuration, firmware version baseline.
Printers / MFDs
Network interface restrictions, admin password policy, audit logging, data storage settings.
Practices

Practices Satisfied

Practice IDDescription
CM.L2-3.4.1 Establish and maintain baseline configurations and inventories of organizational systems throughout the respective system development life cycles.
CM.L2-3.4.2 Establish and enforce security configuration settings for information technology products employed in organizational systems.
CM.L2-3.4.3 Track, review, approve, and log changes to organizational systems.
Connected Modules

Related Modules

Built for the DIB.

1TEN tracks your control posture across all 110 NIST SP 800-171 requirements and generates C3PAO-ready documentation automatically.

Request a Demo