Knowledge is Power

Sitewide Search

Search Bare Metal Cyber

Search courses, individual lessons, wiki entries, books, podcasts, magazine articles, Daily Cyber News, and Darwin.

NIST SP 800-53 Learning Center

CM-3 — Configuration Change Control

Read the official control and assessment content, then use the separately labeled Bare Metal Cyber perspective to connect the requirement to implementation, evidence, and sustained operation.

8Enhancements
5Parameters
2Baseline memberships
3Assessment methods

CM — Configuration Management · NIST SP 800-53 Release 5.2.0

ModerateHigh
Official NIST control content

Control statement

  1. a.Determine and document the types of changes to the system that are configuration-controlled;
  2. b.Review proposed configuration-controlled changes to the system and approve or disapprove such changes with explicit consideration for security and privacy impact analyses;
  3. c.Document configuration change decisions associated with the system;
  4. d.Implement approved configuration-controlled changes to the system;
  5. e.Retain records of configuration-controlled changes to the system for [Organization-defined: time period];
  6. f.Monitor and review activities associated with configuration-controlled changes to the system; and
  7. g.Coordinate and provide oversight for configuration change control activities through [Organization-defined: configuration change control element] that convenes [Organization-defined: cm-03_odp.03].
Official NIST discussion

Discussion

Configuration change control for organizational systems involves the systematic proposal, justification, implementation, testing, review, and disposition of system changes, including system upgrades and modifications. Configuration change control includes changes to baseline configurations, configuration items of systems, operational procedures, configuration settings for system components, remediate vulnerabilities, and unscheduled or unauthorized changes. Processes for managing configuration changes to systems include Configuration Control Boards or Change Advisory Boards that review and approve proposed changes. For changes that impact privacy risk, the senior agency official for privacy updates privacy impact assessments and system of records notices. For new systems or major upgrades, organizations consider including representatives from the development organizations on the Configuration Control Boards or Change Advisory Boards. Auditing of changes includes activities before and after changes are made to systems and the auditing activities required to implement such changes. See also [SA-10](#sa-10).

Official OSCAL parameters

Organization-defined parameters

These values must be resolved through the organization’s tailoring and governance process. Bracketed parameter references in the control text identify where a decision is required.

time periodthe time period to retain records of configuration-controlled changes is defined;
configuration change control elementthe configuration change control element responsible for coordinating and overseeing change control activities is defined;
cm-03_odp.03
frequencythe frequency at which the configuration control element convenes is defined (if selected);
configuration change conditionsconfiguration change conditions that prompt the configuration control element to convene are defined (if selected);
Original Bare Metal Cyber perspective

From control text to operational evidence

Use Configuration Change Control as a testable risk decision. Translate the official statement into accountable people, repeatable processes, configured technology, and evidence that demonstrates the outcome over time. In this family, pay particular attention to secure baselines, controlled change, configuration visibility, and drift management.

Implementation workflow

  • Define the control boundary, responsible owner, inherited portions, and systems or processes in scope.
  • Resolve each organization-defined parameter before declaring the control implemented.
  • Document how the implementation satisfies every clause of the official control statement.
  • Collect evidence as a normal byproduct of operation rather than only before an assessment.
  • Review exceptions, changes, and monitoring results on a risk-based cadence.

Evidence examples

  • approved baseline configurations
  • change tickets and approvals
  • configuration scans and drift reports
  • software and hardware inventories

Common failure patterns

  • baselines documented but not enforced
  • emergency changes never reconciled
  • asset inventories that omit cloud or ephemeral resources
  • security-impact analysis performed after deployment

Questions practitioners should ask

  • What risk decision is this control intended to support in this system?
  • Which parts are implemented locally, inherited, shared, or not applicable—and what evidence supports that decision?
  • Do the documented narrative, deployed configuration, operating process, and collected evidence agree?
  • What event or threshold requires the implementation to be reviewed or changed?
Official NIST SP 800-53A content

Assessment objectives and methods

Show the assessment objective
  1. CM-03a.the types of changes to the system that are configuration-controlled are determined and documented;
  2. CM-03b.
    1. CM-03b.[01]proposed configuration-controlled changes to the system are reviewed;
    2. CM-03b.[02]proposed configuration-controlled changes to the system are approved or disapproved with explicit consideration for security and privacy impact analyses;
  3. CM-03c.configuration change decisions associated with the system are documented;
  4. CM-03d.approved configuration-controlled changes to the system are implemented;
  5. CM-03e.records of configuration-controlled changes to the system are retained for [Organization-defined: time period];
  6. CM-03f.
    1. CM-03f.[01]activities associated with configuration-controlled changes to the system are monitored;
    2. CM-03f.[02]activities associated with configuration-controlled changes to the system are reviewed;
  7. CM-03g.
    1. CM-03g.[01]configuration change control activities are coordinated and overseen by [Organization-defined: configuration change control element];
    2. CM-03g.[02]the configuration control element convenes [Organization-defined: cm-03_odp.03].

Examine

  • Configuration management policy
  • procedures addressing system configuration change control
  • configuration management plan
  • system architecture and configuration documentation
  • change control records
  • system audit records
  • change control audit and review reports
  • agenda/minutes/documentation from configuration change control oversight meetings
  • system security plan
  • privacy plan
  • privacy impact assessments
  • system of records notices
  • other relevant documents or records

Interview

  • Organizational personnel with configuration change control responsibilities
  • organizational personnel with information security and privacy responsibilities
  • system/network administrators
  • members of change control board or similar

Test

  • Organizational processes for configuration change control
  • mechanisms that implement configuration change control
Official relationships

Related controls

These relationships come from the official OSCAL catalog. They indicate useful dependencies or context, not automatic inheritance or equivalence.

Official NIST enhancements

Control enhancements

Enhancements add specificity, strength, or scope to the base control. Baseline badges show explicit selections in the official SP 800-53B OSCAL profiles.

Official NIST control enhancement

CM-3(1) — Automated Documentation, Notification, and Prohibition of Changes

High

Use [Organization-defined: automated mechanisms] to:

  1. (a)Document proposed changes to the system;
  2. (b)Notify [Organization-defined: approval authorities] of proposed changes to the system and request change approval;
  3. (c)Highlight proposed changes to the system that have not been approved or disapproved within [Organization-defined: time period];
  4. (d)Prohibit changes to the system until designated approvals are received;
  5. (e)Document all changes to the system; and
  6. (f)Notify [Organization-defined: personnel] when approved changes to the system are completed.
Official discussion

None.

Organization-defined parameters (4)
automated mechanismsmechanisms used to automate configuration change control are defined;
approval authoritiesapproval authorities to be notified of and request approval for proposed changes to the system are defined;
time periodthe time period after which to highlight changes that have not been approved or disapproved is defined;
personnelpersonnel to be notified when approved changes are complete is/are defined;
Assessment objectives and methods
  1. CM-03(01)(a)[Organization-defined: automated mechanisms] are used to document proposed changes to the system;
  2. CM-03(01)(b)[Organization-defined: automated mechanisms] are used to notify [Organization-defined: approval authorities] of proposed changes to the system and request change approval;
  3. CM-03(01)(c)[Organization-defined: automated mechanisms] are used to highlight proposed changes to the system that have not been approved or disapproved within [Organization-defined: time period];
  4. CM-03(01)(d)[Organization-defined: automated mechanisms] are used to prohibit changes to the system until designated approvals are received;
  5. CM-03(01)(e)[Organization-defined: automated mechanisms] are used to document all changes to the system;
  6. CM-03(01)(f)[Organization-defined: automated mechanisms] are used to notify [Organization-defined: personnel] when approved changes to the system are completed.

Examine

  • Configuration management policy
  • procedures addressing system configuration change control
  • configuration management plan
  • system design documentation
  • system architecture and configuration documentation
  • automated configuration control mechanisms
  • system configuration settings and associated documentation
  • change control records
  • system audit records
  • change approval requests
  • change approvals
  • system security plan
  • other relevant documents or records

Interview

  • Organizational personnel with configuration change control responsibilities
  • organizational personnel with information security responsibilities
  • system/network administrators
  • system developers
  • members of change control board or similar

Test

  • Organizational processes for configuration change control
  • automated mechanisms implementing configuration change control activities
Official NIST control enhancement

CM-3(2) — Testing, Validation, and Documentation of Changes

ModerateHigh

Test, validate, and document changes to the system before finalizing the implementation of the changes.

Official discussion

Changes to systems include modifications to hardware, software, or firmware components and configuration settings defined in [CM-6](#cm-6) . Organizations ensure that testing does not interfere with system operations that support organizational mission and business functions. Individuals or groups conducting tests understand security and privacy policies and procedures, system security and privacy policies and procedures, and the health, safety, and environmental risks associated with specific facilities or processes. Operational systems may need to be taken offline, or replicated to the extent feasible, before testing can be conducted. If systems must be taken offline for testing, the tests are scheduled to occur during planned system outages whenever possible. If the testing cannot be conducted on operational systems, organizations employ compensating controls.

Assessment objectives and methods
  1. CM-03(02)[01]changes to the system are tested before finalizing the implementation of the changes;
  2. CM-03(02)[02]changes to the system are validated before finalizing the implementation of the changes;
  3. CM-03(02)[03]changes to the system are documented before finalizing the implementation of the changes.

Examine

  • Configuration management policy
  • configuration management plan
  • procedures addressing system configuration change control
  • system design documentation
  • system architecture and configuration documentation
  • system configuration settings and associated documentation
  • test records
  • validation records
  • change control records
  • system audit records
  • system security plan
  • other relevant documents or records

Interview

  • Organizational personnel with configuration change control responsibilities
  • organizational personnel with information security responsibilities
  • system/network administrators
  • system developers
  • members of change control board or similar

Test

  • Organizational processes for configuration change control
  • mechanisms supporting and/or implementing, testing, validating, and documenting system changes
Official NIST control enhancement

CM-3(3) — Automated Change Implementation

Implement changes to the current system baseline and deploy the updated baseline across the installed base using [Organization-defined: automated mechanisms].

Official discussion

Automated tools can improve the accuracy, consistency, and availability of configuration baseline information. Automation can also provide data aggregation and data correlation capabilities, alerting mechanisms, and dashboards to support risk-based decision-making within the organization.

Organization-defined parameters (1)
automated mechanismsmechanisms used to automate the implementation of changes and deployment of the updated baseline across the installed base are defined;
Assessment objectives and methods
  1. CM-03(03)[01]changes to the current system baseline are implemented using [Organization-defined: automated mechanisms];
  2. CM-03(03)[02]the updated baseline is deployed across the installed base using [Organization-defined: automated mechanisms].

Examine

  • Configuration management policy
  • configuration management plan
  • procedures addressing system configuration change control
  • system design documentation
  • system architecture and configuration documentation
  • automated configuration control mechanisms
  • change control records
  • system component inventory
  • system audit records
  • system security plan
  • other relevant documents or records

Interview

  • Organizational personnel with configuration change control responsibilities
  • organizational personnel with information security responsibilities
  • system/network administrators
  • system developers
  • members of change control board or similar

Test

  • Organizational processes for configuration change control
  • automated mechanisms implementing changes to current system baseline
Official NIST control enhancement

CM-3(4) — Security and Privacy Representatives

ModerateHigh

Require [Organization-defined: organization-defined security and privacy representatives] to be members of the [Organization-defined: configuration change control element].

Official discussion

Information security and privacy representatives include system security officers, senior agency information security officers, senior agency officials for privacy, or system privacy officers. Representation by personnel with information security and privacy expertise is important because changes to system configurations can have unintended side effects, some of which may be security- or privacy-relevant. Detecting such changes early in the process can help avoid unintended, negative consequences that could ultimately affect the security and privacy posture of systems. The configuration change control element referred to in the second organization-defined parameter reflects the change control elements defined by organizations in [CM-3g](#cm-3_smt.g).

Organization-defined parameters (4)
organization-defined security and privacy representatives
security representativessecurity representatives required to be members of the change control element are defined;
privacy representativesprivacy representatives required to be members of the change control element are defined;
configuration change control elementthe configuration change control element of which the security and privacy representatives are to be members is defined;
Assessment objectives and methods
  1. CM-03(04)[01][Organization-defined: security representatives] are required to be members of the [Organization-defined: configuration change control element];
  2. CM-03(04)[02][Organization-defined: privacy representatives] are required to be members of the [Organization-defined: configuration change control element].

Examine

  • Configuration management policy
  • procedures addressing system configuration change control
  • configuration management plan
  • system security plan
  • privacy plan
  • other relevant documents or records

Interview

  • Organizational personnel with configuration change control responsibilities
  • organizational personnel with information security and privacy responsibilities
  • members of change control board or similar

Test

  • Organizational processes for configuration change control
Official NIST control enhancement

CM-3(5) — Automated Security Response

Implement the following security responses automatically if baseline configurations are changed in an unauthorized manner: [Organization-defined: security responses].

Official discussion

Automated security responses include halting selected system functions, halting system processing, and issuing alerts or notifications to organizational personnel when there is an unauthorized modification of a configuration item.

Organization-defined parameters (1)
security responsessecurity responses to be automatically implemented are defined;
Assessment objectives and methods

[Organization-defined: security responses] are automatically implemented if baseline configurations are changed in an unauthorized manner.

Examine

  • System security plan
  • configuration management policy
  • procedures addressing system configuration change control
  • configuration management plan
  • system design documentation
  • system architecture and configuration documentation
  • system configuration settings and associated documentation
  • alerts/notifications of unauthorized baseline configuration changes
  • system audit records
  • other relevant documents or records

Interview

  • Organizational personnel with configuration change control responsibilities
  • organizational personnel with information security responsibilities
  • system/network administrators
  • system developers
  • members of change control board or similar

Test

  • Organizational processes for configuration change control
  • automated mechanisms implementing security responses to unauthorized changes to the baseline configurations
Official NIST control enhancement

CM-3(6) — Cryptography Management

High

Ensure that cryptographic mechanisms used to provide the following controls are under configuration management: [Organization-defined: controls].

Official discussion

The controls referenced in the control enhancement refer to security and privacy controls from the control catalog. Regardless of the cryptographic mechanisms employed, processes and procedures are in place to manage those mechanisms. For example, if system components use certificates for identification and authentication, a process is implemented to address the expiration of those certificates.

Organization-defined parameters (1)
controlscontrols provided by cryptographic mechanisms that are to be under configuration management are defined;
Assessment objectives and methods

cryptographic mechanisms used to provide [Organization-defined: controls] are under configuration management.

Examine

  • Configuration management policy
  • procedures addressing system configuration change control
  • configuration management plan
  • system design documentation
  • system architecture and configuration documentation
  • system configuration settings and associated documentation
  • system security plan
  • other relevant documents or records

Interview

  • Organizational personnel with configuration change control responsibilities
  • organizational personnel with information security responsibilities
  • system/network administrators
  • system developers
  • members of change control board or similar

Test

  • Organizational processes for configuration change control
  • cryptographic mechanisms implementing organizational security safeguards (controls)
Related controls
Official NIST control enhancement

CM-3(7) — Review System Changes

Review changes to the system [Organization-defined: frequency] or when [Organization-defined: circumstances] to determine whether unauthorized changes have occurred.

Official discussion

Indications that warrant a review of changes to the system and the specific circumstances justifying such reviews may be obtained from activities carried out by organizations during the configuration change process or continuous monitoring process.

Organization-defined parameters (2)
frequencythe frequency at which changes are to be reviewed is defined;
circumstancesthe circumstances under which changes are to be reviewed are defined;
Assessment objectives and methods

changes to the system are reviewed [Organization-defined: frequency] or when [Organization-defined: circumstances] to determine whether unauthorized changes have occurred.

Examine

  • Configuration management policy
  • procedures addressing system configuration change control
  • configuration management plan
  • change control records
  • system architecture and configuration documentation
  • system configuration settings and associated documentation
  • system audit records
  • system component inventory
  • system security plan
  • other relevant documents or records

Interview

  • Organizational personnel with configuration change control responsibilities
  • organizational personnel with security responsibilities
  • system/network administrators
  • members of change control board or similar

Test

  • Organizational processes for configuration change control
  • mechanisms implementing audit records for changes
Related controls
Official NIST control enhancement

CM-3(8) — Prevent or Restrict Configuration Changes

Prevent or restrict changes to the configuration of the system under the following circumstances: [Organization-defined: circumstances].

Official discussion

System configuration changes can adversely affect critical system security and privacy functionality. Change restrictions can be enforced through automated mechanisms.

Organization-defined parameters (1)
circumstancesthe circumstances under which changes are to be prevented or restricted are defined;
Assessment objectives and methods

changes to the configuration of the system are prevented or restricted under [Organization-defined: circumstances].

Examine

  • Configuration management policy
  • procedures addressing system configuration change control
  • configuration management plan
  • change control records
  • system architecture and configuration documentation
  • system configuration settings and associated documentation
  • system component inventory
  • system audit records
  • system security plan
  • other relevant documents or records
Source record

Authoritative sources