Skip to main content
U.S. flag

An official website of the United States government

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Secure .gov websites use HTTPS
A lock ( ) or https:// means you’ve safely connected to the .gov website. Share sensitive information only on official, secure websites.

Managing the Configuration of Information Systems with a Focus on Security



Shirley M. Radack


This bulletin summarizes the information presented in NIST Special Publication (SP) 800-128, Guide to Security-Focused Configuration Management of Information Systems. The publication was written by Arnold Johnson, Kelley Dempsey, and Ron Ross of NIST, and by Sarbari Gupta and Dennis Bailey of Electrosoft. NIST SP 800-128 explains the fundamental concepts associated with security-focused configuration management (SecCM) and its relationship with general configuration management of information systems. The guidelines help organizations develop a well-defined process for managing and controlling secure system configurations, and for managing risks in information systems. The bulletin discusses the contents of the publication, including general concepts, processes, and activities of configuration management, the integration of security-focused configuration management into the configuration management process, and the role of risk management. References are provided to NIST publications that support configuration management and the risk-based management of information systems.
ITL Bulletin -


configuration management, Federal Information Security Management Act, FISMA, information security, information systems, information technology (IT), NIST Special Publications, risk management, Risk Management Framework, SecCM, Security Content Automation Protocol, security controls, security plans, security policies, threats, vulnerabilities


Radack, S. (2011), Managing the Configuration of Information Systems with a Focus on Security, ITL Bulletin, National Institute of Standards and Technology, Gaithersburg, MD, [online], (Accessed May 30, 2024)


If you have any questions about this publication or are having problems accessing it, please contact

Created September 26, 2011, Updated January 27, 2020