U.S. flag   An unofficial archive of your favorite United States government website
Dot gov

Official websites do not use .rip
We are an unofficial archive, replace .rip by .gov in the URL to access the official website. Access our document index here.

Https

We are building a provable archive!
A lock (Dot gov) or https:// don't prove our archive is authentic, only that you securely accessed it. Note that we are working to fix that :)

This is an archive
(replace .gov by .rip)

SP 800-128

Guide for Security-Focused Configuration Management of Information Systems

Date Published: August 2011 (includes updates as of 10-10-2019)

Supersedes: SP 800-128 (08/12/2011)

Author(s)

L. Johnson (NIST), Kelley Dempsey (NIST), Ron Ross (NIST), Sarbari Gupta (Electrosoft Services), Dennis Bailey (Electrosoft Services)

Abstract

Keywords

Configuration management; information systems; security program; risk management framework; security-focused continuous monitoring; SecCM; control; monitoring; security content automation protocol (SCAP)
Control Families

Configuration Management

Documentation

Publication:
SP 800-128 (DOI)
Local Download

Supplemental Material:
None available

Document History:
10/10/19: SP 800-128 (Final)