3.4.7Close unnecessary ports and services
Nonessential programs, ports, protocols, and services are disabled or blocked.
The requirement, verbatim
NIST SP 800-171 Rev. 2 · 3.4.7Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services.
NIST's discussion
Restricting the use of nonessential software (programs) includes restricting the roles allowed to approve program execution; prohibiting auto-execute; program blacklisting and whitelisting; or restricting the number of program instances executed at the same time. The organization makes a security-based determination which functions, ports, protocols, and/or services are restricted. Bluetooth, File Transfer Protocol (FTP), and peer-to-peer networking are examples of protocols organizations consider preventing the use of, restricting, or disabling.
NIST SP 800-171 Rev. 2, discussion under 3.4.7. Whitespace normalised; wording unchanged.
Assessment objectives
An assessor decides each of these separately. The requirement is met only when every objective is.
- [a] essential programs are defined
- [b] the use of nonessential programs is defined
- [c] the use of nonessential programs is restricted, disabled, or prevented as defined
- [d] essential functions are defined
- [e] the use of nonessential functions is defined
- [f] the use of nonessential functions is restricted, disabled, or prevented as defined
- [g] essential ports are defined
- [h] the use of nonessential ports is defined
- [i] the use of nonessential ports is restricted, disabled, or prevented as defined
- [j] essential protocols are defined
- [k] the use of nonessential protocols is defined
- [l] the use of nonessential protocols is restricted, disabled, or prevented as defined
- [m] essential services are defined
- [n] the use of nonessential services is defined
- [o] the use of nonessential services is restricted, disabled, or prevented as defined
NIST SP 800-171A, determination statements for 3.4.7.
For assessors: examine, interview, test
NIST SP 800-171A names what an assessor may examine, whom they may interview, and what they may test for this requirement. Assessors select from these lists; they are not a checklist of everything you must produce.
Examine
- Configuration management policy
- procedures addressing least functionality in the system
- configuration management plan
- system security plan
- system design documentation
- security configuration checklists
- system configuration settings and associated documentation
- specifications for preventing software program execution
- documented reviews of programs, functions, ports, protocols, and/or services
- change control records
- system audit logs and records
- other relevant documents or records
Interview
- Personnel with responsibilities for reviewing programs, functions, ports, protocols, and services on the system
- personnel with information security responsibilities
- system or network administrators
- system developers
Test
- Organizational processes for reviewing and disabling nonessential programs, functions, ports, protocols, or services
- mechanisms implementing review and handling of nonessential programs, functions, ports, protocols, or services
- organizational processes preventing program execution on the system
- organizational processes for software program usage and restrictions
- mechanisms supporting or implementing software program usage and restrictions
- mechanisms preventing program execution on the system
NIST SP 800-171A, potential assessment methods and objects for 3.4.7.
Evidence
No evidence examples are published for this requirement yet. The objectives above are what an assessor checks; evidence is whatever shows each one is true in your environment, dated and kept with your system security plan.
Scoring weight
Worth 5 points. Not meeting this requirement subtracts 5 from your 110-point SPRS score. These are the requirements with the largest effect on your posture.
DoD NIST SP 800-171 Assessment Methodology v1.2.1 weighting, as carried in the Bedrock scoring table. The score starts at 110 and subtracts the weight of every requirement not met.
In Rev. 3
Rev. 2 is what your contract requires today. A standing DoD class deviation keeps Rev. 2 in force; NIST has published Rev. 3, but it is not adopted for contracts. In Rev. 3 this requirement is withdrawn and incorporated elsewhere: 03.04.06 Least Functionality, 03.04.08 Authorized Software – Allow by Exception.
See the Rev. 2 and Rev. 3 wording word by word, or start with the status page.
Related requirements
Where this page's facts come from
- Requirement text
- bedrock-cmmc-api@89b8e8e:migrations/004_reference_requirements.sql#Requirement.basicRequirement@rev2
- Discussion
- bedrock-cmmc-api@89b8e8e:migrations/004_reference_requirements.sql#Requirement.discussion@rev2
- Practice name
- bedrock-cmmc-api@89b8e8e:migrations/004_reference_requirements.sql#Requirement.title@rev2 (CMMC Assessment Guide practice name)
- Objectives
- bedrock-cmmc-api@89b8e8e:migrations/005_reference_objectives.sql#AssessmentObjective.description@rev2
- Examine, interview, test
- bedrock-cmmc-api@89b8e8e:migrations/005_reference_objectives.sql#AssessmentObjective.description@rev2 ({examineGuidance, interviewGuidance, testGuidance})
- Level
- bedrock-cmmc-api@89b8e8e:migrations/021_fix_level1_requirements.sql#Requirement.cmmcLevel@rev2
- Weight
- bedrock-cmmc-api@89b8e8e:internal/cmmc/requirement_values.go#requirementValues (DoD AM v1.2.1 / eMASS L2 template v3.8)
- Rev. 3 mapping
- bedrock-cmmc-api@89b8e8e:docs/reference/nist-800-171-rev3/normalized/r2_r3_transition_map.json#r2_to_r3
- Plain-language title and summary
- editorial/CMMC Navigator.dc.html#RAW (Foxx Cyber editorial)