# Config compliance results proving the ports you declared unnecessary are not reachable from the internet and the software you declared prohibited is not installed, plus the actual installed-application set a periodic review has to read

> FedRAMP Consolidated Rules for 2026 v2026.07.14.01 · updated 2026-07-14
> Canonical page: /collect/config-least-functionality

Recipe id: `config-least-functionality` · cadence monthly · partial

> **Authored opinion.** AWS overlay v3.0.0, written
> against dataset 2026.07.14.01. The upstream
> FedRAMP rules name none of these tools; this mapping is ours.

## What it proves

- KSI `KSI-CMT-RMV`
- KSI `KSI-SVC-EIS`
- KSI `KSI-CNA-RNT`
- control `cm-7`
- control `cm-7.1`

## Collection

Kind: `cli`

```sh
# restricted-common-ports
aws configservice get-compliance-details-by-config-rule --config-rule-name restricted-common-ports --compliance-types NON_COMPLIANT
# ec2-managedinstance-applications-blacklisted
aws configservice get-compliance-details-by-config-rule --config-rule-name ec2-managedinstance-applications-blacklisted --compliance-types NON_COMPLIANT
# list-inventory-entries
aws ssm list-inventory-entries --instance-id i-0123456789abcdef0 --type-name AWS:Application
```

## Expected output

Two EvaluationResults arrays plus an inventory listing. Empty NON_COMPLIANT sets mean no security group opens a blocked TCP port to 0.0.0.0/0 or ::/0 and none of the denylisted applications is installed on any evaluated managed node; the Entries list, stamped with its CaptureTime, is the installed-software set your periodic review actually reads. Managed rule identifiers: RESTRICTED_INCOMING_TRAFFIC (rule name restricted-common-ports), EC2_MANAGEDINSTANCE_APPLICATIONS_BLACKLISTED

## Assertions

_No machine-checkable assertion is authored for this recipe._

## GovCloud

AWS Config, both managed rules, and Systems Manager Inventory are available in AWS GovCloud (US); security-group and node ARNs use partition arn:aws-us-gov

## Notes

These prove the negatives you asserted and hand the reviewer the real installed-application set — they do not prove least functionality. That the functions, ports, protocols and services still enabled are the minimum necessary is a judgement against your documented essential-capability list, and CM-07.01's periodic review is a decision someone makes and records, not an API result; keep the review record next to this output. Both rules are only as strong as their parameters. RESTRICTED_INCOMING_TRAFFIC defaults to blocking TCP 20, 21, 3389, 3306 and 4333 — set blockedPorts to your real denylist or you are testing AWS's defaults, not your policy. EC2_MANAGEDINSTANCE_APPLICATIONS_BLACKLISTED needs exact application names (no wildcards, and the name differs per distro) and evaluates AWS::SSM::ManagedInstanceInventory, so a node with no running agent or inventory association is simply not evaluated rather than flagged — pair it with the inventory recipe's coverage check. Security-group ingress deliberately overlaps the SC-07 boundary recipe: there it proves boundary protection, here it proves unnecessary ports are closed.

## References

- {"title":"AWS Config managed rule: restricted-common-ports (RESTRICTED_INCOMING_TRAFFIC)","url":"https://docs.aws.amazon.com/config/latest/developerguide/restricted-common-ports.html"}
- {"title":"AWS Config managed rule: ec2-managedinstance-applications-blacklisted","url":"https://docs.aws.amazon.com/config/latest/developerguide/ec2-managedinstance-applications-blacklisted.html"}
- {"title":"AWS CLI: ssm list-inventory-entries","url":"https://docs.aws.amazon.com/cli/latest/reference/ssm/list-inventory-entries.html"}
