NIST 800-53 Configuration Management Compliance for Private Mendix Platform
Last modified: June 2, 2026
Introduction
Documents in this section provide more information about Private Mendix Platform's compliance with the Configuration Management (CM) category of the NIST 800-53 security framework. For each applicable control, we have listed which party (Mendix or the customer) is responsible for which component or aspect.
In general, Mendix is responsible for the Private Mendix Platform, Mendix Operator, Mendix Studio Pro, Mendix Runtime, and so on. Customer responsibilities are related to infra and organization processes. For more information, refer to detailed documentation below.
- CM-04 Security Impact Analysis
- CM-04 (01) Security Impact Analysis - Separate Test Environments
- CM-05 - Access Restrictions for Change
- CM-05 (05) Access Restrictions for Change - Limit Production or Operational Changes
- CM-05 (06) Access Restrictions for Change - Limit Library Privileges
- CM-06 Configuration Settings
- CM-06(01) - Configuration Settings (Automated Central Management, Application, Verification)
- CM-07 - Least Functionality
- CM-07 (01) - Least Functionality (Periodic Review)
- CM-07 (02) - Least Functionality (Prevent Program Execution)
- CM-08 (01) - Information System Component Inventory (Updates During Installations or Removals)
- CM-08 (03) - Information System Component Inventory(Automated Unauthorized Component Detection
- CM-10 (01) - Software Usage Restrictions (Open Source Software)