Verification of Controls
LOW ✓ MODERATE ✓ HIGHRequirements NIST SOURCE
After system changes, verify that the impacted controls are implemented correctly, operating as intended, and producing the desired outcome with regard to meeting the security and privacy requirements for the system.
Discussion (NIST Supplemental Guidance)
Implementation in this context refers to installing changed code in the operational system that may have an impact on security or privacy controls.
Implementation Guidance
Original engineering commentary written for this explorer — not NIST source text and not authoritative guidance.
No engineering interpretation has been authored for CM-4(2) yet. This section is architected to receive it — see the Requirements and Assessment sections above for the authoritative NIST source content in the meantime.
Assessment
Assessment Objectives
- the impacted controls are implemented correctly with regard to meeting the security requirements for the system after system changes;
- the impacted controls are implemented correctly with regard to meeting the privacy requirements for the system after system changes;
- the impacted controls are operating as intended with regard to meeting the security requirements for the system after system changes;
- the impacted controls are operating as intended with regard to meeting the privacy requirements for the system after system changes;
- the impacted controls are producing the desired outcome with regard to meeting the security requirements for the system after system changes;
- the impacted controls are producing the desired outcome with regard to meeting the privacy requirements for the system after system changes.
Examine
[SELECT FROM: Configuration management policy; procedures addressing security impact analyses for changes to the system; procedures addressing privacy impact analyses for changes to the system; privacy risk assessment documentation; configuration management plan; security and privacy impact analysis documentation; privacy impact assessment; analysis tools and associated outputs; change control records; control assessment results; system audit records; system component inventory; system security plan; privacy plan; other relevant documents or records].
Interview
[SELECT FROM: Organizational personnel with responsibility for conducting security and privacy impact analyses; organizational personnel with information security and privacy responsibilities; system/network administrators; security and privacy assessors].
Test
[SELECT FROM: Organizational processes for security and privacy impact analyses; mechanisms supporting and/or implementing security and privacy impact analyses of changes].
Overlays
STIGs & CCIs
No STIG checks or CCI mappings are currently loaded for CM-4(2). This section is architected to display, per product: STIG ID, Finding ID, Severity, Title, Description, Check, Fix, CCI, and NIST control mapping — but nothing is populated here until a real DISA STIG/CCI dataset is ingested.
Learn more about STIG/CCI integration →Evidence
Categorized from the SP 800-53A "Examine"/"Test" artifact list above by keyword — not an authoritative NIST evidence list.
Policy
- system security plan
- privacy plan
Configuration
- Configuration management policy
- configuration management plan
- system component inventory
Testing
- Organizational processes for security and privacy impact analyses
- mechanisms supporting and/or implementing security and privacy impact analyses of changes
Other Records
- procedures addressing security impact analyses for changes to the system
- procedures addressing privacy impact analyses for changes to the system
- privacy risk assessment documentation
- security and privacy impact analysis documentation
- privacy impact assessment
- analysis tools and associated outputs
- change control records
- control assessment results
- system audit records
- other relevant documents or records