← CM-4

Verification of Controls

LOW ✓ MODERATE ✓ HIGH
1 Overlay 3 Related Controls
Graph
Export ▾

Requirements NIST SOURCE

After system changes, verify that the impacted controls are implemented correctly, operating as intended, and producing the desired outcome with regard to meeting the security and privacy requirements for the system.

Discussion (NIST Supplemental Guidance)

Implementation in this context refers to installing changed code in the operational system that may have an impact on security or privacy controls.

Implementation Guidance

Engineering Interpretation

Original engineering commentary written for this explorer — not NIST source text and not authoritative guidance.

No engineering interpretation has been authored for CM-4(2) yet. This section is architected to receive it — see the Requirements and Assessment sections above for the authoritative NIST source content in the meantime.

Assessment

NIST SP 800-53A REV 5.2.0

Assessment Objectives

  1. the impacted controls are implemented correctly with regard to meeting the security requirements for the system after system changes;
  2. the impacted controls are implemented correctly with regard to meeting the privacy requirements for the system after system changes;
  3. the impacted controls are operating as intended with regard to meeting the security requirements for the system after system changes;
  4. the impacted controls are operating as intended with regard to meeting the privacy requirements for the system after system changes;
  5. the impacted controls are producing the desired outcome with regard to meeting the security requirements for the system after system changes;
  6. the impacted controls are producing the desired outcome with regard to meeting the privacy requirements for the system after system changes.

Examine

[SELECT FROM: Configuration management policy; procedures addressing security impact analyses for changes to the system; procedures addressing privacy impact analyses for changes to the system; privacy risk assessment documentation; configuration management plan; security and privacy impact analysis documentation; privacy impact assessment; analysis tools and associated outputs; change control records; control assessment results; system audit records; system component inventory; system security plan; privacy plan; other relevant documents or records].

Interview

[SELECT FROM: Organizational personnel with responsibility for conducting security and privacy impact analyses; organizational personnel with information security and privacy responsibilities; system/network administrators; security and privacy assessors].

Test

[SELECT FROM: Organizational processes for security and privacy impact analyses; mechanisms supporting and/or implementing security and privacy impact analyses of changes].

Overlays

Showing the OT/ICS overlay for the parent control CM-4 — see the CM-4(2) entries within each baseline below.

OT/ICS Overlay SP 800-82r3

NIST SP 800-82r3 Appendix F, Table 22. Blank baseline means the control/control enhancement is not selected in that initial OT baseline.

LOW

  • Base control: Included (matches standard baseline)

MODERATE

  • Base control: Included (matches standard baseline)
  • Included: (2)

HIGH

  • Base control: Included (matches standard baseline)
  • Included: (1) (2)

STIGs & CCIs

No STIG checks or CCI mappings are currently loaded for CM-4(2). This section is architected to display, per product: STIG ID, Finding ID, Severity, Title, Description, Check, Fix, CCI, and NIST control mapping — but nothing is populated here until a real DISA STIG/CCI dataset is ingested.

Learn more about STIG/CCI integration →

Evidence

Potential Evidence — Derived

Categorized from the SP 800-53A "Examine"/"Test" artifact list above by keyword — not an authoritative NIST evidence list.

Policy

  • system security plan
  • privacy plan

Configuration

  • Configuration management policy
  • configuration management plan
  • system component inventory

Testing

  • Organizational processes for security and privacy impact analyses
  • mechanisms supporting and/or implementing security and privacy impact analyses of changes

Other Records

  • procedures addressing security impact analyses for changes to the system
  • procedures addressing privacy impact analyses for changes to the system
  • privacy risk assessment documentation
  • security and privacy impact analysis documentation
  • privacy impact assessment
  • analysis tools and associated outputs
  • change control records
  • control assessment results
  • system audit records
  • other relevant documents or records