id: "CM-05(01)" title: "Automated Access Enforcement and Audit Records" family: "CM" family_name: "Configuration Management" sort_id: "cm-05.01" priority: "P1" implementation_level: "system" parent: "CM-05" enhancement: True


Enforce access restrictions using {{ insert: param, cm-05.01_odp }} ; and

Automatically generate audit records of the enforcement actions.

Guidance

Organizations log system accesses associated with applying configuration changes to ensure that configuration change control is implemented and to support after-the-fact actions should organizations discover any unauthorized changes.

Assessment Objective: access restrictions for change are enforced using {{ insert: param, cm-05.01_odp }};

Assessment Objective: audit records of enforcement actions are automatically generated.

Configuration management policy

procedures addressing access restrictions for changes to the system

system design documentation

system architecture and configuration documentation

system configuration settings and associated documentation

change control records

system audit records

system security plan

other relevant documents or records

Organizational personnel with logical access control responsibilities

organizational personnel with physical access control responsibilities

organizational personnel with information security responsibilities

system/network administrators

Organizational processes for managing access restrictions to change

automated mechanisms implementing the enforcement of access restrictions for changes to the system

automated mechanisms supporting auditing of enforcement actions