36 MAC Pt. 1, R. 7.1

Configuration Management

Year: 2026Length: 443 wordsOfficial source

Cite as 36 Miss. Admin. Code Pt. 1, R. 7.1

Configuration Management A. Each agency must establish and maintain baseline configurations of agency systems (including hardware, software, and firmware) throughout the respective system development life cycles. B. Each agency must establish and maintain a secure configuration process for agency assets. Review and update documentation annually, or when significant enterprise changes occur. 1. Securely manage network infrastructure. Example implementations include version-controlled-infrastructure-as-code, and the use of secure network protocols, such as SSH and HTTPS as opposed to Telnet and HTTP. 2. Use standard, industry-recommended hardening configuration templates for application infrastructure components. This includes underlying servers, databases, and web servers, and applies to cloud containers, Platform as a Service (PaaS) components, and SaaS components. Do not allow in-house developed software to weaken configuration hardening. C. Each agency must track, review, approve or disapprove, and log meaningful changes to agency systems. 1. This can be accomplished through a number of ways provided they are fully implemented and utilized for all changes. For example, specialized software packages can be licensed for this purpose or for smaller environments, adequately designed spreadsheets could be utilized. Ultimately, as long as all meaningful changes are tracked, reviewed, and approved, the solution to do this is irrelevant. 2. Less meaningful changes that the agency determines doesn’t need to be reviewed and approved should be logged for historical reference. D. Each agency must analyze the security impact of changes prior to implementation and ensure documentation is updated. 1. Any configuration change which is identified as resulting in a meaningful impact to the agency’s functionality (i.e. installation of new software or hardware, implementation of new methods for granting or removing access, etc.) should be reviewed, its impact considered, and the change documented prior to its rollout. E. Each agency must review, approve or disapprove, and enforce physical and logical access restrictions associated with changes to agency systems. 1. These access appointments should be documented or otherwise logged via either logical or physical mediums, such as permission delegation via Active Directory or physical sign-in sheets placed at entry points. F. Each agency must employ the principle of least functionality by configuring agency systems to provide only essential capabilities. G. Each agency must uninstall or disable unnecessary services on enterprise assets and software, such as an unused file sharing service, web application module, or service function. H. Each agency must use technical controls (when possible), such as application allowlisting, to ensure that only authorized software can execute or be accessed. Reassess this allowlist bi-annually at minimum, or more often if significant change to software inventory necessitates. I. ITS recommends using software inventory tools, when possible, throughout the enterprise to automate the discovery and documentation of installed software.
36 MAC Pt. 1, R. 7.1: Configuration Management | Justis AI