Independent DIB implementation resource — not affiliated with or endorsed by the U.S. Department of WarView the official DoW campaign ↗
3.4.7OFFICIAL STATEMENT BELOWDERIVED REQUIREMENTPENDING NIST SME REVIEW

3.4.7Nonessential functionality restriction

3.4 Configuration Management · NIST SP 800-171 Rev. 2 · The heading label is this site's navigational shorthand; the official language is the statement below.

Official requirement statement (verbatim)

Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services.

NIST SP 800-171 Rev. 2 — Protecting CUI in Nonfederal SystemsNIST SP 800-171A — Assessing Security Requirements for CUI
Independent interpretation

What this requirement is after

The follow-through on least functionality: nonessential programs, ports, protocols, and services are actually restricted, disabled, or prevented — not just frowned upon. Legacy protocols nobody remembers enabling are the classic finding here.

Across revisions

Withdrawn as a standalone requirement in Rev. 3 (the 03.04.07 slot is marked withdrawn); restricting nonessential functions is carried inside Least Functionality, 03.04.06.

Mapped practices

Brilliant at the Basics practices that support this requirement

Doing the work

Implementation considerations and evidence

Implementation considerationsIndependent guidance — tailor to your environment
  • Enumerate what is listening: a port scan of your own estate against an approved-services list finds what documentation forgot.
  • Disable the known-bad legacy set deliberately — SMBv1, Telnet, unencrypted management interfaces — and record the decision per protocol.
  • Re-check on a cadence, because updates and new software re-enable services with no announcement.
What operating evidence looks likeRecords worth retaining, not a submission checklist
  • The approved ports, protocols, and services list
  • Scan results reconciled against that list, dated and repeated
Artifacts

Templates and worksheets with a mapped relationship

No artifact in the library names this requirement yet. The library index groups everything by category and practice.

The other revision

Where this lands in Rev. 3

Provenance

Sources and review status

Primary sourcesNIST SP 800-171 Rev. 2 — Protecting CUI in Nonfederal Systems · NIST SP 800-171A — Assessing Security Requirements for CUI
Review statusPending NIST SME review
Content version1.0
Updated