id: "CM-05" title: "Access Restrictions for Change" family: "CM" family_name: "Configuration Management" sort_id: "cm-05" priority: "P1" implementation_level: "organization" enhancements: - cm-5.1 - cm-5.2 - cm-5.3 - cm-5.4 - cm-5.5 - cm-5.6 - cm-5.7
Statement
Define, document, approve, and enforce physical and logical access restrictions associated with changes to the system.
Guidance
Changes to the hardware, software, or firmware components of systems or the operational procedures related to the system can potentially have significant effects on the security of the systems or individuals’ privacy. Therefore, organizations permit only qualified and authorized individuals to access systems for purposes of initiating changes. Access restrictions include physical and logical access controls (see AC-3 and PE-3 ), software libraries, workflow automation, media libraries, abstract layers (i.e., changes implemented into external interfaces rather than directly into systems), and change windows (i.e., changes occur only during specified times).
Assessment Objective: physical access restrictions associated with changes to the system are defined and documented;
Assessment Objective: physical access restrictions associated with changes to the system are approved;
Assessment Objective: physical access restrictions associated with changes to the system are enforced;
Assessment Objective: logical access restrictions associated with changes to the system are defined and documented;
Assessment Objective: logical access restrictions associated with changes to the system are approved;
Assessment Objective: logical access restrictions associated with changes to the system are enforced.
Configuration management policy
procedures addressing access restrictions for changes to the system
configuration management plan
system design documentation
system architecture and configuration documentation
system configuration settings and associated documentation
logical access approvals
physical access approvals
access credentials
change control records
system audit records
system security plan
other relevant documents or records
Organizational personnel with logical access control responsibilities
organizational personnel with physical access control responsibilities
organizational personnel with information security responsibilities
system/network administrators
Organizational processes for managing access restrictions to change
mechanisms supporting, implementing, or enforcing access restrictions associated with changes to the system