36 MAC Pt. 1, R. 7.1
Configuration Management
Cite as 36 Miss. Admin. Code Pt. 1, R. 7.1
Configuration Management
A. Each agency must establish and maintain baseline configurations of agency systems
(including hardware, software, and firmware) throughout the respective system
development life cycles.
B. Each agency must establish and maintain a secure configuration process for agency
assets. Review and update documentation annually, or when significant enterprise
changes occur.
1. Securely manage network infrastructure. Example implementations include
version-controlled-infrastructure-as-code, and the use of secure network
protocols, such as SSH and HTTPS as opposed to Telnet and HTTP.
2. Use standard, industry-recommended hardening configuration templates for
application infrastructure components. This includes underlying servers,
databases, and web servers, and applies to cloud containers, Platform as a
Service (PaaS) components, and SaaS components. Do not allow in-house
developed software to weaken configuration hardening.
C. Each agency must track, review, approve or disapprove, and log meaningful changes
to agency systems.
1. This can be accomplished through a number of ways provided they are fully
implemented and utilized for all changes. For example, specialized software
packages can be licensed for this purpose or for smaller environments,
adequately designed spreadsheets could be utilized. Ultimately, as long as all
meaningful changes are tracked, reviewed, and approved, the solution to do
this is irrelevant.
2. Less meaningful changes that the agency determines doesn’t need to be
reviewed and approved should be logged for historical reference.
D. Each agency must analyze the security impact of changes prior to implementation and
ensure documentation is updated.
1. Any configuration change which is identified as resulting in a meaningful
impact to the agency’s functionality (i.e. installation of new software or
hardware, implementation of new methods for granting or removing access,
etc.) should be reviewed, its impact considered, and the change documented
prior to its rollout.
E. Each agency must review, approve or disapprove, and enforce physical and logical
access restrictions associated with changes to agency systems.
1. These access appointments should be documented or otherwise logged via
either logical or physical mediums, such as permission delegation via Active
Directory or physical sign-in sheets placed at entry points.
F. Each agency must employ the principle of least functionality by configuring agency
systems to provide only essential capabilities.
G. Each agency must uninstall or disable unnecessary services on enterprise assets and
software, such as an unused file sharing service, web application module, or service
function.
H. Each agency must use technical controls (when possible), such as application
allowlisting, to ensure that only authorized software can execute or be accessed.
Reassess this allowlist bi-annually at minimum, or more often if significant change to
software inventory necessitates.
I. ITS recommends using software inventory tools, when possible, throughout the
enterprise to automate the discovery and documentation of installed software.