Independent DIB implementation resource — not affiliated with or endorsed by the U.S. Department of WarView the official DoW campaign ↗
03.04.01OFFICIAL TITLEPENDING NIST SME REVIEW

03.04.01Baseline Configuration

03.04 Configuration Management · NIST SP 800-171 Rev. 3

Independent summary of the official requirement

Requires developing and maintaining, under configuration control, a current baseline configuration of the system, and reviewing and updating that baseline at an organization-defined frequency and when system components are installed or modified.

Rev. 3 requirement text is multi-part and parameterized with organization-defined values, so this site summarizes rather than reproduces it. The summary is independent — read the official publication for the binding wording.

NIST SP 800-171 Rev. 3 — Protecting CUI in Nonfederal SystemsNIST SP 800-171A Rev. 3 — Assessing Security Requirements for CUI
Independent interpretation

What this requirement is after

For every core system there is a written answer to 'how is this thing supposed to be configured?' — kept current, kept under change control, and revisited when components change. Without it, drift is undetectable, because there is nothing to drift from.

Across revisions

Rev. 2's 3.4.1 splits: baseline configuration stays here, and the component inventory becomes its own requirement, 03.04.10.

Mapped practices

Brilliant at the Basics practices that support this requirement

Direct implementation supportHigh confidence

Why: A current baseline configuration can only be developed and kept current for components the organization knows it has, and the practice's reconciled inventory of hardware, software, and applications is that substrate. The relationship was seeded against Rev. 2's 3.4.1, where baselines and inventories were one requirement.

What this does not claim: Rev. 3 narrows this requirement to the baseline configuration itself — the inventory half of Rev. 2's 3.4.1 now lives in 03.04.10, where this practice maps on its own terms. Inventory work identifies what exists; it does not author, version, or review the baseline documents this requirement is about, and it does not satisfy the requirement on its own.

Practice-side activities
  • Maintain the authoritative component list baseline documents are scoped against
  • Flag inventory changes — new hardware, new software — that should trigger a baseline review
Evidence this produces
  • Inventory reports aligned to baseline document scope
  • Change records showing inventory-triggered baseline updates

Where this holds: The relationship is to the baseline's factual substrate, not its authorship; baseline documentation and review are separate work whatever the inventory's quality.

Review status: Technical review complete · Reviewed by inDirectIT practitioner review — CUI security and NIST SP 800-171 engineering · updated 2026-08-06

Doing the work

Implementation considerations and evidence

Implementation considerationsIndependent guidance — tailor to your environment
  • Scope 'baseline' realistically: a one-page build sheet per core system type — OS version, hardening applied, agents installed, network settings — is a real baseline for a small estate.
  • Put baseline documents under version control so the current one is unambiguous and history survives staff turnover.
  • Tie the update trigger to the change process: a component install or modification should update the baseline in the same motion (see 03.04.03).
What operating evidence looks likeRecords worth retaining, not a submission checklist
  • Current baseline documents per system type, versioned and owned
  • Dated review and update records, including updates triggered by component change

Suggested owners, derived from the mapped practices and artifacts: IT leader · System administrator. Ownership is a named person in your organization, not a role on a website.

Artifacts

Templates and worksheets with a mapped relationship

The other revision

Where this came from in Rev. 2

Provenance

Sources and review status

Primary sourcesNIST SP 800-171 Rev. 3 — Protecting CUI in Nonfederal Systems · NIST SP 800-171A Rev. 3 — Assessing Security Requirements for CUI
Review statusPending NIST SME review
Content version1.0
Updated