The principle of least functionality (for example, limiting services, limiting applications, limiting ports, limiting connected devices) is enforced
Assets should be configured to provide only essential capabilities and to restrict unnecessary functionality. For example, if a system is configured to operate as an email server, ports not associated with this service should be closed and applications/services should be disabled if they do not support the sending and receiving of email.
Related Practices · Progression: This practice is part of a practice progression. Practice progressions are groups of related practices that represent increasingly complete or more advanced implementations of an activity. The practices in this progression include: ARCHITECTURE-3a, ARCHITECTURE-3b, ARCHITECTURE-3c, ARCHITECTURE-3d, ARCHITECTURE-3h, ARCHITECTURE-3k.