Annex 6.3.1
Mapped SPARTA techniques (7)
Techniques referencing this article
Configuration-management obligations cover the whitelist baseline as part of the documented configuration whose deviations must be detected and reviewed.
OS-layer attack surface (maintenance shells, management consoles, kernel parameters) is governed by configuration-management obligations: the entity must establish, document, implement and monitor configurations to keep these primitives off and constrained.
Configuration-management obligations cover application and subscriber tables as part of the documented configuration baseline whose deviations must be detected and reviewed.
Configuration-management obligations cover task-scheduling configuration as part of the documented baseline whose deviations must be detected and reviewed.
Configuration-management obligations cover C&DH-runtime tables as part of the documented configuration baseline subject to deviation detection.
Configuration management of build infrastructure (compiler versions, container base images, plug-in inventories) is the procedural lever that detects and blocks malicious modification of the toolchain that turns source into flight binaries.
Configuration management of the development environment (IDEs, cross-compilers, container images, build agents) is the implementing-regulation control that defines and protects the development substrate the technique enumerates.