Control statement
- a.Determine and document the types of changes to the system that are configuration-controlled;
- b.Review proposed configuration-controlled changes to the system and approve or disapprove such changes with explicit consideration for security and privacy impact analyses;
- c.Document configuration change decisions associated with the system;
- d.Implement approved configuration-controlled changes to the system;
- e.Retain records of configuration-controlled changes to the system for [Organization-defined: time period];
- f.Monitor and review activities associated with configuration-controlled changes to the system; and
- g.Coordinate and provide oversight for configuration change control activities through [Organization-defined: configuration change control element] that convenes [Organization-defined: cm-03_odp.03].
Discussion
Configuration change control for organizational systems involves the systematic proposal, justification, implementation, testing, review, and disposition of system changes, including system upgrades and modifications. Configuration change control includes changes to baseline configurations, configuration items of systems, operational procedures, configuration settings for system components, remediate vulnerabilities, and unscheduled or unauthorized changes. Processes for managing configuration changes to systems include Configuration Control Boards or Change Advisory Boards that review and approve proposed changes. For changes that impact privacy risk, the senior agency official for privacy updates privacy impact assessments and system of records notices. For new systems or major upgrades, organizations consider including representatives from the development organizations on the Configuration Control Boards or Change Advisory Boards. Auditing of changes includes activities before and after changes are made to systems and the auditing activities required to implement such changes. See also [SA-10](#sa-10).
Organization-defined parameters
These values must be resolved through the organization’s tailoring and governance process. Bracketed parameter references in the control text identify where a decision is required.
From control text to operational evidence
Use Configuration Change Control as a testable risk decision. Translate the official statement into accountable people, repeatable processes, configured technology, and evidence that demonstrates the outcome over time. In this family, pay particular attention to secure baselines, controlled change, configuration visibility, and drift management.
Implementation workflow
- Define the control boundary, responsible owner, inherited portions, and systems or processes in scope.
- Resolve each organization-defined parameter before declaring the control implemented.
- Document how the implementation satisfies every clause of the official control statement.
- Collect evidence as a normal byproduct of operation rather than only before an assessment.
- Review exceptions, changes, and monitoring results on a risk-based cadence.
Evidence examples
- approved baseline configurations
- change tickets and approvals
- configuration scans and drift reports
- software and hardware inventories
Common failure patterns
- baselines documented but not enforced
- emergency changes never reconciled
- asset inventories that omit cloud or ephemeral resources
- security-impact analysis performed after deployment
Questions practitioners should ask
- What risk decision is this control intended to support in this system?
- Which parts are implemented locally, inherited, shared, or not applicable—and what evidence supports that decision?
- Do the documented narrative, deployed configuration, operating process, and collected evidence agree?
- What event or threshold requires the implementation to be reviewed or changed?
Assessment objectives and methods
Show the assessment objective
- CM-03a.the types of changes to the system that are configuration-controlled are determined and documented;
- CM-03b.
- CM-03b.[01]proposed configuration-controlled changes to the system are reviewed;
- CM-03b.[02]proposed configuration-controlled changes to the system are approved or disapproved with explicit consideration for security and privacy impact analyses;
- CM-03c.configuration change decisions associated with the system are documented;
- CM-03d.approved configuration-controlled changes to the system are implemented;
- CM-03e.records of configuration-controlled changes to the system are retained for [Organization-defined: time period];
- CM-03f.
- CM-03f.[01]activities associated with configuration-controlled changes to the system are monitored;
- CM-03f.[02]activities associated with configuration-controlled changes to the system are reviewed;
- CM-03g.
- CM-03g.[01]configuration change control activities are coordinated and overseen by [Organization-defined: configuration change control element];
- CM-03g.[02]the configuration control element convenes [Organization-defined: cm-03_odp.03].
Examine
- Configuration management policy
- procedures addressing system configuration change control
- configuration management plan
- system architecture and configuration documentation
- change control records
- system audit records
- change control audit and review reports
- agenda/minutes/documentation from configuration change control oversight meetings
- system security plan
- privacy plan
- privacy impact assessments
- system of records notices
- other relevant documents or records
Interview
- Organizational personnel with configuration change control responsibilities
- organizational personnel with information security and privacy responsibilities
- system/network administrators
- members of change control board or similar
Test
- Organizational processes for configuration change control
- mechanisms that implement configuration change control
Related controls
These relationships come from the official OSCAL catalog. They indicate useful dependencies or context, not automatic inheritance or equivalence.
Control enhancements
Enhancements add specificity, strength, or scope to the base control. Baseline badges show explicit selections in the official SP 800-53B OSCAL profiles.
CM-3(1) — Automated Documentation, Notification, and Prohibition of Changes
Use [Organization-defined: automated mechanisms] to:
- (a)Document proposed changes to the system;
- (b)Notify [Organization-defined: approval authorities] of proposed changes to the system and request change approval;
- (c)Highlight proposed changes to the system that have not been approved or disapproved within [Organization-defined: time period];
- (d)Prohibit changes to the system until designated approvals are received;
- (e)Document all changes to the system; and
- (f)Notify [Organization-defined: personnel] when approved changes to the system are completed.
Official discussion
None.
Organization-defined parameters (4)
Assessment objectives and methods
- CM-03(01)(a)[Organization-defined: automated mechanisms] are used to document proposed changes to the system;
- CM-03(01)(b)[Organization-defined: automated mechanisms] are used to notify [Organization-defined: approval authorities] of proposed changes to the system and request change approval;
- CM-03(01)(c)[Organization-defined: automated mechanisms] are used to highlight proposed changes to the system that have not been approved or disapproved within [Organization-defined: time period];
- CM-03(01)(d)[Organization-defined: automated mechanisms] are used to prohibit changes to the system until designated approvals are received;
- CM-03(01)(e)[Organization-defined: automated mechanisms] are used to document all changes to the system;
- CM-03(01)(f)[Organization-defined: automated mechanisms] are used to notify [Organization-defined: personnel] when approved changes to the system are completed.
Examine
- Configuration management policy
- procedures addressing system configuration change control
- configuration management plan
- system design documentation
- system architecture and configuration documentation
- automated configuration control mechanisms
- system configuration settings and associated documentation
- change control records
- system audit records
- change approval requests
- change approvals
- system security plan
- other relevant documents or records
Interview
- Organizational personnel with configuration change control responsibilities
- organizational personnel with information security responsibilities
- system/network administrators
- system developers
- members of change control board or similar
Test
- Organizational processes for configuration change control
- automated mechanisms implementing configuration change control activities
CM-3(2) — Testing, Validation, and Documentation of Changes
Test, validate, and document changes to the system before finalizing the implementation of the changes.
Official discussion
Changes to systems include modifications to hardware, software, or firmware components and configuration settings defined in [CM-6](#cm-6) . Organizations ensure that testing does not interfere with system operations that support organizational mission and business functions. Individuals or groups conducting tests understand security and privacy policies and procedures, system security and privacy policies and procedures, and the health, safety, and environmental risks associated with specific facilities or processes. Operational systems may need to be taken offline, or replicated to the extent feasible, before testing can be conducted. If systems must be taken offline for testing, the tests are scheduled to occur during planned system outages whenever possible. If the testing cannot be conducted on operational systems, organizations employ compensating controls.
Assessment objectives and methods
- CM-03(02)[01]changes to the system are tested before finalizing the implementation of the changes;
- CM-03(02)[02]changes to the system are validated before finalizing the implementation of the changes;
- CM-03(02)[03]changes to the system are documented before finalizing the implementation of the changes.
Examine
- Configuration management policy
- configuration management plan
- procedures addressing system configuration change control
- system design documentation
- system architecture and configuration documentation
- system configuration settings and associated documentation
- test records
- validation records
- change control records
- system audit records
- system security plan
- other relevant documents or records
Interview
- Organizational personnel with configuration change control responsibilities
- organizational personnel with information security responsibilities
- system/network administrators
- system developers
- members of change control board or similar
Test
- Organizational processes for configuration change control
- mechanisms supporting and/or implementing, testing, validating, and documenting system changes
CM-3(3) — Automated Change Implementation
Implement changes to the current system baseline and deploy the updated baseline across the installed base using [Organization-defined: automated mechanisms].
Official discussion
Automated tools can improve the accuracy, consistency, and availability of configuration baseline information. Automation can also provide data aggregation and data correlation capabilities, alerting mechanisms, and dashboards to support risk-based decision-making within the organization.
Organization-defined parameters (1)
Assessment objectives and methods
- CM-03(03)[01]changes to the current system baseline are implemented using [Organization-defined: automated mechanisms];
- CM-03(03)[02]the updated baseline is deployed across the installed base using [Organization-defined: automated mechanisms].
Examine
- Configuration management policy
- configuration management plan
- procedures addressing system configuration change control
- system design documentation
- system architecture and configuration documentation
- automated configuration control mechanisms
- change control records
- system component inventory
- system audit records
- system security plan
- other relevant documents or records
Interview
- Organizational personnel with configuration change control responsibilities
- organizational personnel with information security responsibilities
- system/network administrators
- system developers
- members of change control board or similar
Test
- Organizational processes for configuration change control
- automated mechanisms implementing changes to current system baseline
CM-3(4) — Security and Privacy Representatives
Require [Organization-defined: organization-defined security and privacy representatives] to be members of the [Organization-defined: configuration change control element].
Official discussion
Information security and privacy representatives include system security officers, senior agency information security officers, senior agency officials for privacy, or system privacy officers. Representation by personnel with information security and privacy expertise is important because changes to system configurations can have unintended side effects, some of which may be security- or privacy-relevant. Detecting such changes early in the process can help avoid unintended, negative consequences that could ultimately affect the security and privacy posture of systems. The configuration change control element referred to in the second organization-defined parameter reflects the change control elements defined by organizations in [CM-3g](#cm-3_smt.g).
Organization-defined parameters (4)
Assessment objectives and methods
- CM-03(04)[01][Organization-defined: security representatives] are required to be members of the [Organization-defined: configuration change control element];
- CM-03(04)[02][Organization-defined: privacy representatives] are required to be members of the [Organization-defined: configuration change control element].
Examine
- Configuration management policy
- procedures addressing system configuration change control
- configuration management plan
- system security plan
- privacy plan
- other relevant documents or records
Interview
- Organizational personnel with configuration change control responsibilities
- organizational personnel with information security and privacy responsibilities
- members of change control board or similar
Test
- Organizational processes for configuration change control
CM-3(5) — Automated Security Response
Implement the following security responses automatically if baseline configurations are changed in an unauthorized manner: [Organization-defined: security responses].
Official discussion
Automated security responses include halting selected system functions, halting system processing, and issuing alerts or notifications to organizational personnel when there is an unauthorized modification of a configuration item.
Organization-defined parameters (1)
Assessment objectives and methods
[Organization-defined: security responses] are automatically implemented if baseline configurations are changed in an unauthorized manner.
Examine
- System security plan
- configuration management policy
- procedures addressing system configuration change control
- configuration management plan
- system design documentation
- system architecture and configuration documentation
- system configuration settings and associated documentation
- alerts/notifications of unauthorized baseline configuration changes
- system audit records
- other relevant documents or records
Interview
- Organizational personnel with configuration change control responsibilities
- organizational personnel with information security responsibilities
- system/network administrators
- system developers
- members of change control board or similar
Test
- Organizational processes for configuration change control
- automated mechanisms implementing security responses to unauthorized changes to the baseline configurations
CM-3(6) — Cryptography Management
Ensure that cryptographic mechanisms used to provide the following controls are under configuration management: [Organization-defined: controls].
Official discussion
The controls referenced in the control enhancement refer to security and privacy controls from the control catalog. Regardless of the cryptographic mechanisms employed, processes and procedures are in place to manage those mechanisms. For example, if system components use certificates for identification and authentication, a process is implemented to address the expiration of those certificates.
Organization-defined parameters (1)
Assessment objectives and methods
cryptographic mechanisms used to provide [Organization-defined: controls] are under configuration management.
Examine
- Configuration management policy
- procedures addressing system configuration change control
- configuration management plan
- system design documentation
- system architecture and configuration documentation
- system configuration settings and associated documentation
- system security plan
- other relevant documents or records
Interview
- Organizational personnel with configuration change control responsibilities
- organizational personnel with information security responsibilities
- system/network administrators
- system developers
- members of change control board or similar
Test
- Organizational processes for configuration change control
- cryptographic mechanisms implementing organizational security safeguards (controls)
Related controls
CM-3(7) — Review System Changes
Review changes to the system [Organization-defined: frequency] or when [Organization-defined: circumstances] to determine whether unauthorized changes have occurred.
Official discussion
Indications that warrant a review of changes to the system and the specific circumstances justifying such reviews may be obtained from activities carried out by organizations during the configuration change process or continuous monitoring process.
Organization-defined parameters (2)
Assessment objectives and methods
changes to the system are reviewed [Organization-defined: frequency] or when [Organization-defined: circumstances] to determine whether unauthorized changes have occurred.
Examine
- Configuration management policy
- procedures addressing system configuration change control
- configuration management plan
- change control records
- system architecture and configuration documentation
- system configuration settings and associated documentation
- system audit records
- system component inventory
- system security plan
- other relevant documents or records
Interview
- Organizational personnel with configuration change control responsibilities
- organizational personnel with security responsibilities
- system/network administrators
- members of change control board or similar
Test
- Organizational processes for configuration change control
- mechanisms implementing audit records for changes
Related controls
CM-3(8) — Prevent or Restrict Configuration Changes
Prevent or restrict changes to the configuration of the system under the following circumstances: [Organization-defined: circumstances].
Official discussion
System configuration changes can adversely affect critical system security and privacy functionality. Change restrictions can be enforced through automated mechanisms.
Organization-defined parameters (1)
Assessment objectives and methods
changes to the configuration of the system are prevented or restricted under [Organization-defined: circumstances].
Examine
- Configuration management policy
- procedures addressing system configuration change control
- configuration management plan
- change control records
- system architecture and configuration documentation
- system configuration settings and associated documentation
- system component inventory
- system audit records
- system security plan
- other relevant documents or records
Authoritative sources
Bare Metal Cyber is an independent educational publisher and is not affiliated with or endorsed by NIST. Official control requirements and interpretations remain with NIST and the responsible authorizing organization.