id: "CM-05(05)" title: "Privilege Limitation for Production and Operation" family: "CM" family_name: "Configuration Management" sort_id: "cm-05.05" priority: "P1" implementation_level: "organization" parent: "CM-05" enhancement: True
Limit privileges to change system components and system-related information within a production or operational environment; and
Review and reevaluate privileges {{ insert: param, cm-5.5_prm_1 }}.
Guidance
In many organizations, systems support multiple mission and business functions. Limiting privileges to change system components with respect to operational systems is necessary because changes to a system component may have far-reaching effects on mission and business processes supported by the system. The relationships between systems and mission/business processes are, in some cases, unknown to developers. System-related information includes operational procedures.
Assessment Objective: privileges to change system components within a production or operational environment are limited;
Assessment Objective: privileges to change system-related information within a production or operational environment are limited;
Assessment Objective: privileges are reviewed {{ insert: param, cm-05.05_odp.01 }};
Assessment Objective: privileges are reevaluated {{ insert: param, cm-05.05_odp.02 }}.
Configuration management policy
procedures addressing access restrictions for changes to the system
configuration management plan
system design documentation
system architecture and configuration documentation
system configuration settings and associated documentation
user privilege reviews
user privilege recertifications
system component inventory
change control records
system audit records
system security plan
other relevant documents or records
Organizational personnel with information security responsibilities
system/network administrators
Organizational processes for managing access restrictions to change
mechanisms supporting and/or implementing access restrictions for change