1Overview
CM.L2-3.4.7 is the most granular expression of least functionality, and the largest requirement in the guide by objective count. It requires that the organization restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services, so that each of those five categories is reduced to what the work actually needs. It is a five-point requirement that cannot be deferred on a plan of action.
Where 3.4.6 sets the principle of least functionality, this control applies it concretely across five specific categories. Every program installed, function enabled, port open, protocol allowed, and service running is a potential path for an attacker, and most systems carry many of each that no one needs. The control asks the organization to decide, for each category, what is essential and what is not, and to restrict, disable, or prevent the nonessential. Its fifteen assessment objectives come from applying three steps, define essential, define nonessential, and restrict the nonessential, to each of the five categories.
Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services.
The five categories are worth naming because each is a distinct surface: programs are installed applications, functions are capabilities within systems and applications, ports are network endpoints, protocols are the languages of communication, and services are background processes. For each, the organization identifies what is essential and what is not, and then restricts, disables, or prevents the nonessential. The fifteen objectives are simply this pattern applied five times, and the five-point weight reflects how much attack surface these categories carry when left unmanaged.
2The Assessment Objectives
NIST SP 800-171A decomposes 3.4.7 into fifteen objectives, applying three steps, define essential, define nonessential, and restrict, disable, or prevent, to each of programs, functions, ports, protocols, and services.
Essential programs are defined. The organization has identified the programs that are needed.
The use of nonessential programs is defined. The organization has identified the programs that are not needed.
The use of nonessential programs is restricted, disabled, or prevented. Those nonessential programs are actually removed or blocked.
Essential functions are defined. The organization has identified the functions that are needed.
The use of nonessential functions is defined. The organization has identified the functions that are not needed.
The use of nonessential functions is restricted, disabled, or prevented. Those nonessential functions are actually disabled or blocked.
Essential ports are defined. The organization has identified the network ports that are needed.
The use of nonessential ports is defined. The organization has identified the ports that are not needed.
The use of nonessential ports is restricted, disabled, or prevented. Those nonessential ports are actually closed or blocked.
Essential protocols are defined. The organization has identified the protocols that are needed.
The use of nonessential protocols is defined. The organization has identified the protocols that are not needed.
The use of nonessential protocols is restricted, disabled, or prevented. Those nonessential protocols are actually disabled or blocked.
Essential services are defined. The organization has identified the services that are needed.
The use of nonessential services is defined. The organization has identified the services that are not needed.
The use of nonessential services is restricted, disabled, or prevented. Those nonessential services are actually disabled or blocked.
The fifteen objectives are the same three-step pattern across five categories. The common gap is at the restriction objectives, [c], [f], [i], [l], and [o], where essential and nonessential are identified but the nonessential is not actually restricted, so open ports, running services, and installed programs that no one needs remain in place. The assessor looks for the nonessential in each category to be genuinely restricted, disabled, or prevented.
3Failure Patterns
The failures are about unmanaged categories and identification without restriction.
Open ports and running services no one needs
Systems commonly run services and expose ports that no one uses but an attacker can reach. Identifying and closing or disabling the nonessential ones removes a large part of the network attack surface, and leaving them fails the restriction objectives.
Legacy protocols left enabled
Outdated or insecure protocols left enabled for convenience are a frequent weakness, since they are often the easiest thing for an attacker to exploit. Disabling the nonessential protocols is part of the control.
Extra programs and functions installed
Systems loaded with applications and features beyond what the work needs carry programs and functions an attacker can use. Removing or disabling the nonessential ones reduces that surface.
Identified but not restricted
Where the nonessential items in a category are identified but never actually restricted, disabled, or prevented, the restriction objective for that category is unmet. Identification has to lead to action across all five categories.
4Ownership
This is an IT-owned technical control, and its work is methodically reducing each of the five categories to the essential.
| Role | Responsibility for this control |
|---|---|
| IT and system administrator | Identifies essential and nonessential programs, functions, ports, protocols, and services, and restricts, disables, or prevents the nonessential. Owns the technical evidence. |
| Security or compliance lead | Confirms each category is reduced to the essential and that restriction is actually applied. |
| Program lead | Includes the five categories in periodic review as new items appear, and retains the evidence. |
5Tooling
The control is delivered by hardening, host and network configuration, and the tools that reveal what is actually running and open.
| Categories | Tooling | What it provides |
|---|---|---|
| Programs, functions | Software removal, feature and role management, hardening baselines | Reduction of installed programs and enabled functions to the essential. |
| Ports, protocols | Host and network firewalls, protocol configuration | Closing nonessential ports and disabling nonessential protocols. |
| Services | Service configuration, disabling unneeded services | Stopping and disabling nonessential background services. |
| Discovery | Port and service scanning, configuration review | Visibility of what is actually open and running, so the nonessential can be found. |
The caveat is that all five categories have to be addressed, and identification has to lead to restriction. Discovery reveals what is open and running, but the control is met only when the nonessential is actually closed, disabled, or removed across programs, functions, ports, protocols, and services. The assessor examines each category, so a reduction that covers some but not all leaves the control incomplete.
6Evidence
The satisfied version of 3.4.7 shows each category reduced to the essential.
| Evidence | What it demonstrates |
|---|---|
| Essential and nonessential definitions | Objectives [a], [b], [d], [e], [g], [h], [j], [k], [m], [n]. What is essential and nonessential in each category. |
| Firewall and port configuration | Objective [i]. Nonessential ports closed or blocked. |
| Service and protocol configuration | Objectives [f], [l], [o]. Nonessential functions, protocols, and services disabled. |
| Installed software list | Objective [c]. Nonessential programs removed or prevented. |
The evidence should show the nonessential restricted across all five categories, backed by the definitions of what is essential in each. Configuration and scans demonstrating closed ports, disabled services and protocols, and removed programs, together with the definitions, are the clearest demonstration, and because this control cannot sit on a plan of action, the restriction has to be real at the time of assessment.
Five surfaces, each reduced to what the work needs
Open ports, running services, legacy protocols, and unused programs and functions each give an attacker a path, and this five-point control asks for the nonessential in every category to be restricted. Methodically reducing programs, functions, ports, protocols, and services to the essential is part of the onsite readiness work this practice does, and it is one of the controls that must be met rather than deferred.
Start CMMC Readiness or call 802-335-26627Sources
- NIST Special Publication 800-171 Rev 2, Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations, requirement 3.4.7. csrc.nist.gov
- NIST Special Publication 800-171A, Assessing Security Requirements for Controlled Unclassified Information, assessment objectives 3.4.7[a] through 3.4.7[o]. csrc.nist.gov
- 32 CFR 170.24, CMMC Scoring Methodology, listing CM.L2-3.4.7 among the five-point derived security requirements. ecfr.gov