NIST SP 800-171 & CMMC 2.0 Control 3.4.7 Requirement:

Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services.

NIST SP 800-171 & CMMC 2.0 3.4.7 Requirement Explanation:

By uninstalling nonessential programs and disabling unused ports, protocols, and services you are reducing the attack surface your systems.

Example NIST SP 800-171 & CMMC 2.0 3.4.7 Implementation:

Using your software whitelist (addressed in CM.3.69) as a reference uninstall all nonessential software from your systems. If it doesn't have an approved business need and isn't on your software whitelist, uninstall it. Review your workstations, servers, network devices, and printers to determine which ports and services you can disable. Only leave essential ports and services open.

NIST SP 800-171 & CMMC 2.0 3.4.7 Scenario(s):

- Scenario 1:

You discover that many employees in your organization have iTunes installed on their Windows workstations. Because this is a nonessential program you have it uninstalled from all of your systems.

- Scenario 2:

You have a web server that has several nonessential ports open. You work with your system administrator to only leave the essential ports open.

Discover Our NIST SP 800-171 & CMMC 2.0 Solutions:


Compliance Accelerator

Power through compliance. Meet and maintain your NIST SP 800-171 & CMMC 2.0 compliance requirements.

Quantum Assessor

Transform your business. Create new revenue streams and provide scalability for your NIST SP 800-171 and CMMC 2.0 services.

Supply Chain Verifier

Trust is everything. Verify, monitor, and support subcontactor compliance.