NIST 800-171 Controls · Configuration Management
CM.2.006 — Employ Principle of Least Functionality
Employ the principle of least functionality by configuring organizational systems to provide only essential capabilities.
What CM.2.006 means in plain English
Your work computers should only be able to do what they need to do for the job. A workstation used by machinists to access job orders and drawings does not need Bluetooth enabled, does not need a web browser that can access any website, does not need games, and should not have file-sharing features turned on. Disable or remove everything that is not needed for the business. Fewer features means fewer ways for attackers to get in. This is the IT equivalent of not leaving tools lying around where they do not belong.
The assessment question
“Have systems been configured to disable or remove unnecessary features, ports, protocols, and services not required for business operations, with documentation of what was disabled and why?”
How to implement CM.2.006
- Run the free CIS-CAT Lite tool or manually work through the CIS Benchmark to identify unnecessary Windows features and services. Common items to disable in a machine shop environment: Bluetooth (if not needed), infrared ports, SNMP service, Telnet client, FTP client, Remote Desktop (if not used for IT management), and Windows Media Player.
- Use Windows Programs and Features (Control Panel > Programs > Turn Windows Features On or Off) to remove unused Windows components. Document what was removed and the business rationale.
- Disable unnecessary Windows services: open services.msc and set services like "Routing and Remote Access," "Print Spooler" (on non-print workstations), "Remote Registry," and "Xbox Live" services to Disabled. Document each change in your change log.
- Use Group Policy to restrict access to control panel features that standard users do not need: User Configuration > Administrative Templates > Control Panel.
- Create a "Least Functionality Baseline" document listing every disabled feature, service, and port across your standard workstation configuration. Update this whenever the baseline is changed. This document directly satisfies assessor requests for evidence.
Evidence your assessor will ask for
- "Least Functionality Baseline" document listing disabled features, services, and ports
- Change log entries documenting each feature/service disabled and business justification
- Screenshot of Windows Services showing unnecessary services are Disabled
- Windows Features screenshot showing unused components are removed
- CIS-CAT Lite report or equivalent showing compliance with hardening benchmark
Does AI prompt monitoring help with this control? Honestly, no.
CM.2.006 is met through the remediation steps above, not through AI traffic controls — an AI prompt firewall neither satisfies nor substitutes for it. We map AI monitoring only to the controls it genuinely evidences (flow control, boundary protection, audit, and incident support); for the full picture of where it does help, see the mapping guide linked below.
Full mapping: which 800-171 controls AI prompt monitoring evidences →
More Configuration Management controls
Establish and Maintain Baseline Configurations
CM.2.002Establish and Enforce Security Configuration Settings
CM.2.003Track, Review, Approve, and Log Changes to Systems
CM.2.004Analyze Security Impact of Changes Prior to Implementation
CM.2.005Define and Enforce Access Restrictions for Configuration Changes
CM.2.007Restrict, Disable, or Prevent Use of Nonessential Programs
Score yourself against all 110 controls
The free ShieldReady assessment walks every NIST 800-171 requirement, computes your SPRS score, and shows exactly which gaps cost the most points.