HomeControl Library › 3.4.6
3.4 Configuration Management5 pts

3.4.6 — Least functionality

Employ the principle of least functionality by configuring organizational systems to provide only essential capabilities.

Systems provide only the essential capabilities — nothing extra.

What it actually means

Every extra feature, service, or app is attack surface. Configure systems to do only what they need to do — disable the rest. A web server doesn't need a mail service running; a CUI workstation doesn't need games and torrent clients.

Pass or fail — an assessor needs a "yes" to each

What to have ready

Where teams trip up

See where this control puts your score

Run all 110 requirements free in about 10 minutes.

Calculate your SPRS score →

Connected requirements

← Back to the Control Library