configuration parameter
A named, adjustable variable — such as a setting, flag, threshold, or rule — in the hardware, software, or firmware of a system component whose value determines some aspect of that component's behavior or security posture. Configuration settings (of which configuration parameters are the constituent elements) are "the parameters that can be changed in the hardware, software, or firmware components of the system that affect the security and privacy posture or functionality of the system" (NIST SP 800-53r5, CM-6). Examples span registry settings, file and directory permission settings, settings for functions, protocols, ports, and remote connections, as well as privacy-affecting settings such as access controls, data processing preferences, and processing and retention permissions. In practice, compliance and audit frameworks treat configuration parameters as the lowest-level, individually assessable units of a system's configuration baseline: NIST SP 800-204A, for instance, organizes its deployment recommendations around configuration parameters for service-mesh components as the concrete mechanism by which security requirements for microservices applications are met.
Framework senses
- §1 · attested_usage_reviewer_confirmed
- No definition is given in NIST SP 800-171r3. The term is attested in use at 1 citation in that document; a definition is pending curation.Increment 2: attested in 800-171r3 without a glossary definition.
- §1 · web_lookup_draft
- A named, adjustable variable — such as a setting, flag, threshold, or rule — in the hardware, software, or firmware of a system component whose value determines some aspect of that component's behavior or security posture. Configuration settings (of which configuration parameters are the constituent elements) are "the parameters that can be changed in the hardware, software, or firmware components of the system that affect the security and privacy posture or functionality of the system" (NIST SP 800-53r5, CM-6). Examples span registry settings, file and directory permission settings, settings for functions, protocols, ports, and remote connections, as well as privacy-affecting settings such as access controls, data processing preferences, and processing and retention permissions. In practice, compliance and audit frameworks treat configuration parameters as the lowest-level, individually assessable units of a system's configuration baseline: NIST SP 800-204A, for instance, organizes its deployment recommendations around configuration parameters for service-mesh components as the concrete mechanism by which security requirements for microservices applications are met.DR-088 backfill from the noun definition column