Cyber Resilience

NIST 800-53 r5 · Controls catalogue · Family CM

CM-7Least Functionality

Configure the system to provide only {{ insert: param, cm-07_odp.01 }} ; and Prohibit or restrict the use of the following functions, ports, protocols, software, and/or services: {{ insert: param, cm-7_prm_2 }}.

Last updated: 22 August 2026 07:11 UTC

Implementations targeting this control (3)

ATT&CK techniques this control mitigates (223)

Weaknesses this control addresses (8)AI-assisted

CWEs ranked by how often they appear in real CVEs. The rationale describes how this control reduces exploitability of each weakness class.

CWE Name CVEs Why this control addresses it
CWE-284Improper Access Control6,900+Restricting available functions and services reduces the attack surface and enforces proper access control boundaries.
CWE-306Missing Authentication for Critical Function3,300+Disabling non-essential functions and services eliminates the need to secure them, reducing exposure from missing authentication on unnecessary components.
CWE-732Incorrect Permission Assignment for Critical Resource1,900+Configuring systems to provide only required functionality avoids incorrect permission assignments on unneeded resources, ports, or services.
CWE-285Improper Authorization1,500+By limiting enabled features to only those needed, the control strengthens authorization by removing opportunities for unauthorized use of excess functionality.
CWE-250Execution with Unnecessary Privileges300+Prohibiting unnecessary functions, ports, protocols, software, and services directly prevents execution with privileges beyond what is required for the system's purpose.
CWE-1188Initialization of a Resource with an Insecure Default300+Requiring explicit configuration to minimal functionality overrides insecure defaults that would otherwise enable excess capabilities.
CWE-749Exposed Dangerous Method or Function100+Explicitly prohibiting dangerous or unnecessary functions and services prevents exposure of methods that could be directly exploited.
CWE-272Least Privilege Violation38Enforcing only the minimal set of functionality implements least privilege by eliminating unneeded capabilities that could be abused.

Top CVEs where this control is the strongest mitigation

CVE Risk CVSS EPSS Match
CVE-2024-56346 7.610.00.0109good
CVE-2025-362507.510.00.0067good
CVE-2025-55050 7.29.80.0034partial
CVE-2025-12176 7.29.80.0032partial
CVE-2017-20204 7.09.30.0084partial
CVE-2024-36912 6.99.60.0096partial
CVE-2024-56347 6.99.60.0089good
CVE-2025-362516.89.60.0054good
CVE-2025-15480 6.89.10.0031partial
CVE-2024-36913 6.69.30.0065partial
CVE-2024-5386 6.68.80.0048good
CVE-2023-36346.68.80.0050partial
CVE-2026-747996.69.30.0039good
CVE-2023-49722 6.38.30.0044good
CVE-2025-1950 6.39.30.0019good
CVE-2024-25021 6.28.40.0027good
CVE-2026-29046 6.28.20.0039good
CVE-2025-0160 6.18.10.0050good
CVE-2024-32004 6.08.10.0135good
CVE-2025-417566.08.10.0033partial
CVE-2025-14551 6.08.10.0028partial
CVE-2024-52564 5.97.50.0058partial
CVE-2025-27684 5.97.50.0057good
CVE-2025-34081 5.97.50.0060good
CVE-2025-22450 5.87.50.0038partial

Other controls in family CM

CM-1 CM-10 CM-11 CM-12 CM-13 CM-14 CM-2 CM-3 CM-4 CM-5 CM-6 CM-8 CM-9