id: "CM-05(01)" title: "Automated Access Enforcement and Audit Records" family: "CM" family_name: "Configuration Management" sort_id: "cm-05.01" priority: "P1" implementation_level: "system" parent: "CM-05" enhancement: True
Enforce access restrictions using {{ insert: param, cm-05.01_odp }} ; and
Automatically generate audit records of the enforcement actions.
Guidance
Organizations log system accesses associated with applying configuration changes to ensure that configuration change control is implemented and to support after-the-fact actions should organizations discover any unauthorized changes.
Assessment Objective: access restrictions for change are enforced using {{ insert: param, cm-05.01_odp }};
Assessment Objective: audit records of enforcement actions are automatically generated.
Configuration management policy
procedures addressing access restrictions for changes to the system
system design documentation
system architecture and configuration documentation
system configuration settings and associated documentation
change control records
system audit records
system security plan
other relevant documents or records
Organizational personnel with logical access control responsibilities
organizational personnel with physical access control responsibilities
organizational personnel with information security responsibilities
system/network administrators
Organizational processes for managing access restrictions to change
automated mechanisms implementing the enforcement of access restrictions for changes to the system
automated mechanisms supporting auditing of enforcement actions