Configuration Change Control

LOW ✓ MODERATE ✓ HIGH
8 Enhancements 1 Overlay 23 Related Controls
Graph
Export ▾

Requirements NIST SOURCE

Discussion (NIST Supplemental Guidance)

Configuration change control for organizational systems involves the systematic proposal, justification, implementation, testing, review, and disposition of system changes, including system upgrades and modifications. Configuration change control includes changes to baseline configurations, configuration items of systems, operational procedures, configuration settings for system components, remediate vulnerabilities, and unscheduled or unauthorized changes. Processes for managing configuration changes to systems include Configuration Control Boards or Change Advisory Boards that review and approve proposed changes. For changes that impact privacy risk, the senior agency official for privacy updates privacy impact assessments and system of records notices. For new systems or major upgrades, organizations consider including representatives from the development organizations on the Configuration Control Boards or Change Advisory Boards. Auditing of changes includes activities before and after changes are made to systems and the auditing activities required to implement such changes. See also SA-10.

Enhancements NIST SOURCE

CM-3(1) Automated Documentation, Notification, and Prohibition of Changes LOW MODERATE ✓ HIGH

Use [automated mechanisms] to:

  1. (a) Document proposed changes to the system;
  2. (b) Notify [approval authorities] of proposed changes to the system and request change approval;
  3. (c) Highlight proposed changes to the system that have not been approved or disapproved within [time period];
  4. (d) Prohibit changes to the system until designated approvals are received;
  5. (e) Document all changes to the system; and
  6. (f) Notify [personnel] when approved changes to the system are completed.
Discussion

None.

Open full page for CM-3(1) →
CM-3(2) Testing, Validation, and Documentation of Changes LOW ✓ MODERATE ✓ HIGH

Test, validate, and document changes to the system before finalizing the implementation of the changes.

Discussion

Changes to systems include modifications to hardware, software, or firmware components and configuration settings defined in CM-6 . Organizations ensure that testing does not interfere with system operations that support organizational mission and business functions. Individuals or groups conducting tests understand security and privacy policies and procedures, system security and privacy policies and procedures, and the health, safety, and environmental risks associated with specific facilities or processes. Operational systems may need to be taken offline, or replicated to the extent feasible, before testing can be conducted. If systems must be taken offline for testing, the tests are scheduled to occur during planned system outages whenever possible. If the testing cannot be conducted on operational systems, organizations employ compensating controls.

Open full page for CM-3(2) →
CM-3(3) Automated Change Implementation LOW MODERATE HIGH

Implement changes to the current system baseline and deploy the updated baseline across the installed base using [automated mechanisms].

Discussion

Automated tools can improve the accuracy, consistency, and availability of configuration baseline information. Automation can also provide data aggregation and data correlation capabilities, alerting mechanisms, and dashboards to support risk-based decision-making within the organization.

Open full page for CM-3(3) →
CM-3(4) Security and Privacy Representatives LOW ✓ MODERATE ✓ HIGH

Require [organization-defined security and privacy representatives] to be members of the [configuration change control element].

Discussion

Information security and privacy representatives include system security officers, senior agency information security officers, senior agency officials for privacy, or system privacy officers. Representation by personnel with information security and privacy expertise is important because changes to system configurations can have unintended side effects, some of which may be security- or privacy-relevant. Detecting such changes early in the process can help avoid unintended, negative consequences that could ultimately affect the security and privacy posture of systems. The configuration change control element referred to in the second organization-defined parameter reflects the change control elements defined by organizations in CM-3g.

Open full page for CM-3(4) →
CM-3(5) Automated Security Response LOW MODERATE HIGH

Implement the following security responses automatically if baseline configurations are changed in an unauthorized manner: [security responses].

Discussion

Automated security responses include halting selected system functions, halting system processing, and issuing alerts or notifications to organizational personnel when there is an unauthorized modification of a configuration item.

Open full page for CM-3(5) →
CM-3(6) Cryptography Management LOW MODERATE ✓ HIGH

Ensure that cryptographic mechanisms used to provide the following controls are under configuration management: [controls].

Discussion

The controls referenced in the control enhancement refer to security and privacy controls from the control catalog. Regardless of the cryptographic mechanisms employed, processes and procedures are in place to manage those mechanisms. For example, if system components use certificates for identification and authentication, a process is implemented to address the expiration of those certificates.

Open full page for CM-3(6) →
CM-3(7) Review System Changes LOW MODERATE HIGH

Review changes to the system [frequency] or when [circumstances] to determine whether unauthorized changes have occurred.

Discussion

Indications that warrant a review of changes to the system and the specific circumstances justifying such reviews may be obtained from activities carried out by organizations during the configuration change process or continuous monitoring process.

Open full page for CM-3(7) →
CM-3(8) Prevent or Restrict Configuration Changes LOW MODERATE HIGH

Prevent or restrict changes to the configuration of the system under the following circumstances: [circumstances].

Discussion

System configuration changes can adversely affect critical system security and privacy functionality. Change restrictions can be enforced through automated mechanisms.

Open full page for CM-3(8) →

Implementation Guidance

Engineering Interpretation

Original engineering commentary written for this explorer — not NIST source text and not authoritative guidance.

No engineering interpretation has been authored for CM-3 yet. This section is architected to receive it — see the Requirements and Assessment sections above for the authoritative NIST source content in the meantime.

Assessment

NIST SP 800-53A REV 5.2.0

Assessment Objectives

  1. the time period to retain records of configuration-controlled changes is defined;
  2. the configuration change control element responsible for coordinating and overseeing change control activities is defined;
  3. one or more of the following PARAMETER VALUES is/are selected: { <CM-03_ODP[04] frequency>; when <CM-03_ODP[05] configuration change conditions>};
  4. the frequency at which the configuration control element convenes is defined (if selected);
  5. configuration change conditions that prompt the configuration control element to convene are defined (if selected);
  6. the types of changes to the system that are configuration-controlled are determined and documented;
  7. proposed configuration-controlled changes to the system are reviewed;
  8. proposed configuration-controlled changes to the system are approved or disapproved with explicit consideration for security and privacy impact analyses;
  9. configuration change decisions associated with the system are documented;
  10. approved configuration-controlled changes to the system are implemented;
  11. records of configuration-controlled changes to the system are retained for <CM-03_ODP[01] time period>;
  12. activities associated with configuration-controlled changes to the system are monitored;
  13. activities associated with configuration-controlled changes to the system are reviewed;
  14. configuration change control activities are coordinated and overseen by <CM-03_ODP[02] configuration change control element>;
  15. the configuration control element convenes <CM-03_ODP[03] SELECTED PARAMETER VALUES>.

Examine

[SELECT FROM: Configuration management policy; procedures addressing system configuration change control; configuration management plan; system architecture and configuration documentation; change control records; system audit records; change control audit and review reports; agenda/minutes/documentation from configuration change control oversight meetings; system security plan; privacy plan; privacy impact assessments; system of records notices; other relevant documents or records].

Interview

[SELECT FROM: Organizational personnel with configuration change control responsibilities; organizational personnel with information security and privacy responsibilities; system/network administrators; members of change control board or similar].

Test

[SELECT FROM: Organizational processes for configuration change control; mechanisms that implement configuration change control].

Overlays

OT/ICS Overlay SP 800-82r3

NIST SP 800-82r3 Appendix F, Table 22. Blank baseline means the control/control enhancement is not selected in that initial OT baseline.

LOW

Not applicable at this tier.

MODERATE

  • Base control: Included (matches standard baseline)
  • Included: (2) (4)

HIGH

  • Base control: Included (matches standard baseline)
  • Included: (1) (2) (4) (6)

STIGs & CCIs

No STIG checks or CCI mappings are currently loaded for CM-3. This section is architected to display, per product: STIG ID, Finding ID, Severity, Title, Description, Check, Fix, CCI, and NIST control mapping — but nothing is populated here until a real DISA STIG/CCI dataset is ingested.

Learn more about STIG/CCI integration →

Evidence

Potential Evidence — Derived

Categorized from the SP 800-53A "Examine"/"Test" artifact list above by keyword — not an authoritative NIST evidence list.

Policy

  • system security plan
  • privacy plan

Configuration

  • Configuration management policy
  • procedures addressing system configuration change control
  • configuration management plan
  • system architecture and configuration documentation
  • agenda/minutes/documentation from configuration change control oversight meetings

Testing

  • Organizational processes for configuration change control
  • mechanisms that implement configuration change control

Other Records

  • change control records
  • system audit records
  • change control audit and review reports
  • privacy impact assessments
  • system of records notices
  • other relevant documents or records