The principle of least functionality (for example, limiting services, limiting applications, limiting ports, limiting connected devices) is enforced
Context and Guidance: Assets should be configured to provide only essential capabilities and to restrict unnecessary functionality. For example, if a system is configured to operate as an email server, ports not associated with this service should be closed and applications/services should be disabled if they do not support the sending and receiving of email.
Related Practices • Progression: This practice is part of a practice progression. Practice progressions are groups of related practices that represent increasingly complete or more advanced implementations of an activity. The practices in this progression include: ARCHITECTURE-3a, ARCHITECTURE-3b, ARCHITECTURE-3c, ARCHITECTURE-3d, ARCHITECTURE-3h, ARCHITECTURE-3k.