Knowledge is Power

Sitewide Search

Search Bare Metal Cyber

Search exact control and technique identifiers, Cyber Wiki articles, framework records, playbooks, books, podcasts, Academy courses, and individual lessons.

NIST SP 800-53 Learning Center

CM-5 — Access Restrictions for Change

Read the official control and assessment content, then use the separately labeled Bare Metal Cyber perspective to connect the requirement to implementation, evidence, and sustained operation.

7Enhancements
0Parameters
3Baseline memberships
3Assessment methods

CM — Configuration Management · NIST SP 800-53 Release 5.2.0

LowModerateHigh
Official NIST control content

Control statement

Define, document, approve, and enforce physical and logical access restrictions associated with changes to the system.

Official NIST discussion

Discussion

Changes to the hardware, software, or firmware components of systems or the operational procedures related to the system can potentially have significant effects on the security of the systems or individuals’ privacy. Therefore, organizations permit only qualified and authorized individuals to access systems for purposes of initiating changes. Access restrictions include physical and logical access controls (see [AC-3](#ac-3) and [PE-3](#pe-3) ), software libraries, workflow automation, media libraries, abstract layers (i.e., changes implemented into external interfaces rather than directly into systems), and change windows (i.e., changes occur only during specified times).

Original Bare Metal Cyber perspective

From control text to operational evidence

Use Access Restrictions for Change as a testable risk decision. Translate the official statement into accountable people, repeatable processes, configured technology, and evidence that demonstrates the outcome over time. In this family, pay particular attention to secure baselines, controlled change, configuration visibility, and drift management.

Implementation workflow

  • Define the control boundary, responsible owner, inherited portions, and systems or processes in scope.
  • Resolve each organization-defined parameter before declaring the control implemented.
  • Document how the implementation satisfies every clause of the official control statement.
  • Collect evidence as a normal byproduct of operation rather than only before an assessment.
  • Review exceptions, changes, and monitoring results on a risk-based cadence.

Evidence examples

  • approved baseline configurations
  • change tickets and approvals
  • configuration scans and drift reports
  • software and hardware inventories

Common failure patterns

  • baselines documented but not enforced
  • emergency changes never reconciled
  • asset inventories that omit cloud or ephemeral resources
  • security-impact analysis performed after deployment

Questions practitioners should ask

  • What risk decision is this control intended to support in this system?
  • Which parts are implemented locally, inherited, shared, or not applicable—and what evidence supports that decision?
  • Do the documented narrative, deployed configuration, operating process, and collected evidence agree?
  • What event or threshold requires the implementation to be reviewed or changed?
Official NIST SP 800-53A content

Assessment objectives and methods

Show the assessment objective
  1. CM-05[01]physical access restrictions associated with changes to the system are defined and documented;
  2. CM-05[02]physical access restrictions associated with changes to the system are approved;
  3. CM-05[03]physical access restrictions associated with changes to the system are enforced;
  4. CM-05[04]logical access restrictions associated with changes to the system are defined and documented;
  5. CM-05[05]logical access restrictions associated with changes to the system are approved;
  6. CM-05[06]logical access restrictions associated with changes to the system are enforced.

Examine

  • Configuration management policy
  • procedures addressing access restrictions for changes to the system
  • configuration management plan
  • system design documentation
  • system architecture and configuration documentation
  • system configuration settings and associated documentation
  • logical access approvals
  • physical access approvals
  • access credentials
  • change control records
  • system audit records
  • system security plan
  • other relevant documents or records

Interview

  • Organizational personnel with logical access control responsibilities
  • organizational personnel with physical access control responsibilities
  • organizational personnel with information security responsibilities
  • system/network administrators

Test

  • Organizational processes for managing access restrictions to change
  • mechanisms supporting, implementing, or enforcing access restrictions associated with changes to the system
Official relationships

Related controls

These relationships come from the official OSCAL catalog. They indicate useful dependencies or context, not automatic inheritance or equivalence.

MITRE D3FEND semantic mapping

Related defensive techniques

D3FEND maps this base control or one of its enhancements to the following defensive techniques. The ontology relation label is preserved and does not by itself prove implementation or effectiveness.

MITRE D3FEND™ and the D3FEND logo are trademarks of The MITRE Corporation. Bare Metal Cyber is not affiliated with or endorsed by MITRE.

Official CUI requirement crosswalk

Related NIST SP 800-171 requirements

These Rev. 3 requirements cite this base control or one of its enhancements as a source. The relationship does not by itself determine contractual applicability or complete implementation.

Official CUI requirement crosswalk

Related NIST SP 800-172 requirements

These Rev. 3 requirements cite this base control or one of its enhancements as a source. The relationship does not by itself determine contractual applicability or complete implementation.

Official NIST enhancements

Control enhancements

Enhancements add specificity, strength, or scope to the base control. Baseline badges show explicit selections in the official SP 800-53B OSCAL profiles.

Official NIST control enhancement

CM-5(1) — Automated Access Enforcement and Audit Records

High
  1. (a)Enforce access restrictions using [Organization-defined: automated mechanisms] ; and
  2. (b)Automatically generate audit records of the enforcement actions.
Official discussion

Organizations log system accesses associated with applying configuration changes to ensure that configuration change control is implemented and to support after-the-fact actions should organizations discover any unauthorized changes.

Organization-defined parameters (1)
automated mechanismsmechanisms used to automate the enforcement of access restrictions are defined;
Assessment objectives and methods
  1. CM-05(01)(a)access restrictions for change are enforced using [Organization-defined: automated mechanisms];
  2. CM-05(01)(b)audit records of enforcement actions are automatically generated.

Examine

  • Configuration management policy
  • procedures addressing access restrictions for changes to the system
  • system design documentation
  • system architecture and configuration documentation
  • system configuration settings and associated documentation
  • change control records
  • system audit records
  • system security plan
  • other relevant documents or records

Interview

  • Organizational personnel with logical access control responsibilities
  • organizational personnel with physical access control responsibilities
  • organizational personnel with information security responsibilities
  • system/network administrators

Test

  • Organizational processes for managing access restrictions to change
  • automated mechanisms implementing the enforcement of access restrictions for changes to the system
  • automated mechanisms supporting auditing of enforcement actions
Related controls
Official NIST control enhancement

CM-5(2) — Review System Changes

Withdrawn

This enhancement is marked withdrawn in the official OSCAL catalog. Related-control metadata below may identify where its intent was incorporated.

Official NIST control enhancement

CM-5(3) — Signed Components

Withdrawn

This enhancement is marked withdrawn in the official OSCAL catalog. Related-control metadata below may identify where its intent was incorporated.

Official NIST control enhancement

CM-5(4) — Dual Authorization

Enforce dual authorization for implementing changes to [Organization-defined: organization-defined system components and system-level information].

Official discussion

Organizations employ dual authorization to help ensure that any changes to selected system components and information cannot occur unless two qualified individuals approve and implement such changes. The two individuals possess the skills and expertise to determine if the proposed changes are correct implementations of approved changes. The individuals are also accountable for the changes. Dual authorization may also be known as two-person control. To reduce the risk of collusion, organizations consider rotating dual authorization duties to other individuals. System-level information includes operational procedures.

Organization-defined parameters (3)
organization-defined system components and system-level information
system componentssystem components requiring dual authorization for changes are defined;
system-level informationsystem-level information requiring dual authorization for changes is defined;
Assessment objectives and methods
  1. CM-05(04)[01]dual authorization for implementing changes to [Organization-defined: system components] is enforced;
  2. CM-05(04)[02]dual authorization for implementing changes to [Organization-defined: system-level information] is enforced.

Examine

  • Configuration management policy
  • procedures addressing access restrictions for changes to the system
  • configuration management plan
  • system design documentation
  • system architecture and configuration documentation
  • system configuration settings and associated documentation
  • change control records
  • system audit records
  • system component inventory
  • system information types information
  • system security plan
  • other relevant documents or records

Interview

  • Organizational personnel with dual authorization enforcement responsibilities for implementing system changes
  • organizational personnel with information security responsibilities
  • system/network administrators

Test

  • Organizational processes for managing access restrictions to change
  • mechanisms implementing dual authorization enforcement
Related controls
Official NIST control enhancement

CM-5(5) — Privilege Limitation for Production and Operation

  1. (a)Limit privileges to change system components and system-related information within a production or operational environment; and
  2. (b)Review and reevaluate privileges [Organization-defined: organization-defined frequency].
Official discussion

In many organizations, systems support multiple mission and business functions. Limiting privileges to change system components with respect to operational systems is necessary because changes to a system component may have far-reaching effects on mission and business processes supported by the system. The relationships between systems and mission/business processes are, in some cases, unknown to developers. System-related information includes operational procedures.

Organization-defined parameters (3)
organization-defined frequency
frequencyfrequency at which to review privileges is defined;
frequencyfrequency at which to reevaluate privileges is defined;
Assessment objectives and methods
  1. CM-05(05)(a)
    1. CM-05(05)(a)[01]privileges to change system components within a production or operational environment are limited;
    2. CM-05(05)(a)[02]privileges to change system-related information within a production or operational environment are limited;
  2. CM-05(05)(b)
    1. CM-05(05)(b)[01]privileges are reviewed [Organization-defined: frequency];
    2. CM-05(05)(b)[02]privileges are reevaluated [Organization-defined: frequency].

Examine

  • Configuration management policy
  • procedures addressing access restrictions for changes to the system
  • configuration management plan
  • system design documentation
  • system architecture and configuration documentation
  • system configuration settings and associated documentation
  • user privilege reviews
  • user privilege recertifications
  • system component inventory
  • change control records
  • system audit records
  • system security plan
  • other relevant documents or records

Interview

  • Organizational personnel with information security responsibilities
  • system/network administrators

Test

  • Organizational processes for managing access restrictions to change
  • mechanisms supporting and/or implementing access restrictions for change
Related controls
Official NIST control enhancement

CM-5(6) — Limit Library Privileges

Limit privileges to change software resident within software libraries.

Official discussion

Software libraries include privileged programs.

Assessment objectives and methods

privileges to change software resident within software libraries are limited.

Examine

  • Configuration management policy
  • procedures addressing access restrictions for changes to the system
  • configuration management plan
  • system design documentation
  • system architecture and configuration documentation
  • system configuration settings and associated documentation
  • system component inventory
  • change control records
  • system audit records
  • system security plan
  • other relevant documents or records

Interview

  • Organizational personnel with information security responsibilities
  • system/network administrators

Test

  • Organizational processes for managing access restrictions to change
  • mechanisms supporting and/or implementing access restrictions for change
Related controls
Official NIST control enhancement

CM-5(7) — Automatic Implementation of Security Safeguards

Withdrawn

This enhancement is marked withdrawn in the official OSCAL catalog. Related-control metadata below may identify where its intent was incorporated.

Source record

Authoritative sources