Security requirement
Define, document, approve, and enforce physical and logical access restrictions associated with changes to the system.
Discussion
Changes to the hardware, software, or firmware components of the system or the operational procedures related to the system can have potentially significant effects on the security of the system. Therefore, organizations permit only qualified and authorized individuals to access the system for the purpose of initiating changes. Access restrictions include physical and logical access controls, software libraries, workflow automation, media libraries, abstract layers (i.e., changes implemented into external interfaces rather than directly into the system), and change windows (i.e., changes occur only during specified times).
Implementation perspective
Treat Access Restrictions for Change as a CUI protection outcome that must be reflected in the system boundary, documented implementation, operational behavior, and assessment evidence. Pay particular attention to approved baselines, secure configuration, change control, inventories, and drift management within the CUI boundary.
- Confirm the requirement is in scope for the CUI system components, services, users, and external connections being assessed.
- Resolve every organization-defined parameter through an approved governance and tailoring process.
- Map each clause of the requirement to an accountable owner, implementation mechanism, and evidence source.
- Verify that inherited and shared implementations are supported by current provider evidence and responsibility boundaries.
- Collect evidence during normal operation and review changes, exceptions, and deficiencies on a risk-based cadence.
Questions to ask
- Which CUI assets, data flows, users, and services are protected by this requirement?
- Which portions are implemented locally, inherited, shared, or not applicable, and what evidence supports that determination?
- Do the system security plan, deployed configuration, operating process, and assessment evidence tell the same story?
- What change, incident, or threshold should trigger reassessment?
Evidence and validation
- approved baseline configurations
- change tickets and approvals
- configuration scan and drift reports
- software and hardware inventories
Common failure patterns
- baselines documented but not enforced
- emergency changes never reconciled
- cloud or ephemeral assets missing from inventory
- security impact analysis performed after deployment
Assessment objectives and methods
Assessment objectives (6)
- SR-03.4.5.
physical access restrictions associated with changes to the system are defined and documented.
- SR-03.4.5.
physical access restrictions associated with changes to the system are approved.
- SR-03.4.5.
physical access restrictions associated with changes to the system are enforced.
- SR-03.4.5.
logical access restrictions associated with changes to the system are defined and documented.
- SR-03.4.5.
logical access restrictions associated with changes to the system are approved.
- SR-03.4.5.
logical access restrictions associated with changes to the system are enforced.
Examine
- configuration management policy and procedures
- procedures for access restrictions for system changes
- configuration management plan
- system design documentation
- system architecture
- system configuration settings
- logical access approvals
- physical access approvals
- access credentials
- change control records
- system audit records
- system security plan
- other relevant documents or records
Interview
- personnel with logical access control responsibilities
- personnel with physical access control responsibilities
- personnel with information security responsibilities
- system administrators
Test
- processes for managing access restrictions for system changes
- mechanisms for supporting, implementing, or enforcing access restrictions associated with system changes
Source NIST SP 800-53 controls
These controls are referenced by the official SP 800-171 Rev. 3 OSCAL record. Open the corresponding control pages for complete control text, enhancements, D3FEND mappings, and related learning.
Authoritative sources
- NIST SP 800-171 Revision 3 official publication ↗
- NIST SP 800-171A Revision 3 official publication ↗
- NIST OSCAL Content release used for this import ↗
Bare Metal Cyber is an independent educational publisher and is not affiliated with or endorsed by NIST. The official publications, the responsible federal agency, and the governing contract or agreement determine applicability, tailoring, assessment depth, and required implementation.