Control statement
Define, document, approve, and enforce physical and logical access restrictions associated with changes to the system.
Discussion
Changes to the hardware, software, or firmware components of systems or the operational procedures related to the system can potentially have significant effects on the security of the systems or individuals’ privacy. Therefore, organizations permit only qualified and authorized individuals to access systems for purposes of initiating changes. Access restrictions include physical and logical access controls (see [AC-3](#ac-3) and [PE-3](#pe-3) ), software libraries, workflow automation, media libraries, abstract layers (i.e., changes implemented into external interfaces rather than directly into systems), and change windows (i.e., changes occur only during specified times).
From control text to operational evidence
Use Access Restrictions for Change as a testable risk decision. Translate the official statement into accountable people, repeatable processes, configured technology, and evidence that demonstrates the outcome over time. In this family, pay particular attention to secure baselines, controlled change, configuration visibility, and drift management.
Implementation workflow
- Define the control boundary, responsible owner, inherited portions, and systems or processes in scope.
- Resolve each organization-defined parameter before declaring the control implemented.
- Document how the implementation satisfies every clause of the official control statement.
- Collect evidence as a normal byproduct of operation rather than only before an assessment.
- Review exceptions, changes, and monitoring results on a risk-based cadence.
Evidence examples
- approved baseline configurations
- change tickets and approvals
- configuration scans and drift reports
- software and hardware inventories
Common failure patterns
- baselines documented but not enforced
- emergency changes never reconciled
- asset inventories that omit cloud or ephemeral resources
- security-impact analysis performed after deployment
Questions practitioners should ask
- What risk decision is this control intended to support in this system?
- Which parts are implemented locally, inherited, shared, or not applicable—and what evidence supports that decision?
- Do the documented narrative, deployed configuration, operating process, and collected evidence agree?
- What event or threshold requires the implementation to be reviewed or changed?
Assessment objectives and methods
Show the assessment objective
- CM-05[01]physical access restrictions associated with changes to the system are defined and documented;
- CM-05[02]physical access restrictions associated with changes to the system are approved;
- CM-05[03]physical access restrictions associated with changes to the system are enforced;
- CM-05[04]logical access restrictions associated with changes to the system are defined and documented;
- CM-05[05]logical access restrictions associated with changes to the system are approved;
- CM-05[06]logical access restrictions associated with changes to the system are enforced.
Examine
- Configuration management policy
- procedures addressing access restrictions for changes to the system
- configuration management plan
- system design documentation
- system architecture and configuration documentation
- system configuration settings and associated documentation
- logical access approvals
- physical access approvals
- access credentials
- change control records
- system audit records
- system security plan
- other relevant documents or records
Interview
- Organizational personnel with logical access control responsibilities
- organizational personnel with physical access control responsibilities
- organizational personnel with information security responsibilities
- system/network administrators
Test
- Organizational processes for managing access restrictions to change
- mechanisms supporting, implementing, or enforcing access restrictions associated with changes to the system
Related controls
These relationships come from the official OSCAL catalog. They indicate useful dependencies or context, not automatic inheritance or equivalence.
Related defensive techniques
D3FEND maps this base control or one of its enhancements to the following defensive techniques. The ontology relation label is preserved and does not by itself prove implementation or effectiveness.
MITRE D3FEND™ and the D3FEND logo are trademarks of The MITRE Corporation. Bare Metal Cyber is not affiliated with or endorsed by MITRE.
Related NIST SP 800-171 requirements
These Rev. 3 requirements cite this base control or one of its enhancements as a source. The relationship does not by itself determine contractual applicability or complete implementation.
Related NIST SP 800-172 requirements
These Rev. 3 requirements cite this base control or one of its enhancements as a source. The relationship does not by itself determine contractual applicability or complete implementation.
Control enhancements
Enhancements add specificity, strength, or scope to the base control. Baseline badges show explicit selections in the official SP 800-53B OSCAL profiles.
CM-5(1) — Automated Access Enforcement and Audit Records
- (a)Enforce access restrictions using [Organization-defined: automated mechanisms] ; and
- (b)Automatically generate audit records of the enforcement actions.
Official discussion
Organizations log system accesses associated with applying configuration changes to ensure that configuration change control is implemented and to support after-the-fact actions should organizations discover any unauthorized changes.
Organization-defined parameters (1)
Assessment objectives and methods
- CM-05(01)(a)access restrictions for change are enforced using [Organization-defined: automated mechanisms];
- CM-05(01)(b)audit records of enforcement actions are automatically generated.
Examine
- Configuration management policy
- procedures addressing access restrictions for changes to the system
- system design documentation
- system architecture and configuration documentation
- system configuration settings and associated documentation
- change control records
- system audit records
- system security plan
- other relevant documents or records
Interview
- Organizational personnel with logical access control responsibilities
- organizational personnel with physical access control responsibilities
- organizational personnel with information security responsibilities
- system/network administrators
Test
- Organizational processes for managing access restrictions to change
- automated mechanisms implementing the enforcement of access restrictions for changes to the system
- automated mechanisms supporting auditing of enforcement actions
Related controls
CM-5(2) — Review System Changes
This enhancement is marked withdrawn in the official OSCAL catalog. Related-control metadata below may identify where its intent was incorporated.
CM-5(3) — Signed Components
This enhancement is marked withdrawn in the official OSCAL catalog. Related-control metadata below may identify where its intent was incorporated.
CM-5(4) — Dual Authorization
Enforce dual authorization for implementing changes to [Organization-defined: organization-defined system components and system-level information].
Official discussion
Organizations employ dual authorization to help ensure that any changes to selected system components and information cannot occur unless two qualified individuals approve and implement such changes. The two individuals possess the skills and expertise to determine if the proposed changes are correct implementations of approved changes. The individuals are also accountable for the changes. Dual authorization may also be known as two-person control. To reduce the risk of collusion, organizations consider rotating dual authorization duties to other individuals. System-level information includes operational procedures.
Organization-defined parameters (3)
Assessment objectives and methods
- CM-05(04)[01]dual authorization for implementing changes to [Organization-defined: system components] is enforced;
- CM-05(04)[02]dual authorization for implementing changes to [Organization-defined: system-level information] is enforced.
Examine
- Configuration management policy
- procedures addressing access restrictions for changes to the system
- configuration management plan
- system design documentation
- system architecture and configuration documentation
- system configuration settings and associated documentation
- change control records
- system audit records
- system component inventory
- system information types information
- system security plan
- other relevant documents or records
Interview
- Organizational personnel with dual authorization enforcement responsibilities for implementing system changes
- organizational personnel with information security responsibilities
- system/network administrators
Test
- Organizational processes for managing access restrictions to change
- mechanisms implementing dual authorization enforcement
Related controls
CM-5(5) — Privilege Limitation for Production and Operation
- (a)Limit privileges to change system components and system-related information within a production or operational environment; and
- (b)Review and reevaluate privileges [Organization-defined: organization-defined frequency].
Official discussion
In many organizations, systems support multiple mission and business functions. Limiting privileges to change system components with respect to operational systems is necessary because changes to a system component may have far-reaching effects on mission and business processes supported by the system. The relationships between systems and mission/business processes are, in some cases, unknown to developers. System-related information includes operational procedures.
Organization-defined parameters (3)
Assessment objectives and methods
- CM-05(05)(a)
- CM-05(05)(a)[01]privileges to change system components within a production or operational environment are limited;
- CM-05(05)(a)[02]privileges to change system-related information within a production or operational environment are limited;
- CM-05(05)(b)
- CM-05(05)(b)[01]privileges are reviewed [Organization-defined: frequency];
- CM-05(05)(b)[02]privileges are reevaluated [Organization-defined: frequency].
Examine
- Configuration management policy
- procedures addressing access restrictions for changes to the system
- configuration management plan
- system design documentation
- system architecture and configuration documentation
- system configuration settings and associated documentation
- user privilege reviews
- user privilege recertifications
- system component inventory
- change control records
- system audit records
- system security plan
- other relevant documents or records
Interview
- Organizational personnel with information security responsibilities
- system/network administrators
Test
- Organizational processes for managing access restrictions to change
- mechanisms supporting and/or implementing access restrictions for change
Related controls
CM-5(6) — Limit Library Privileges
Limit privileges to change software resident within software libraries.
Official discussion
Software libraries include privileged programs.
Assessment objectives and methods
privileges to change software resident within software libraries are limited.
Examine
- Configuration management policy
- procedures addressing access restrictions for changes to the system
- configuration management plan
- system design documentation
- system architecture and configuration documentation
- system configuration settings and associated documentation
- system component inventory
- change control records
- system audit records
- system security plan
- other relevant documents or records
Interview
- Organizational personnel with information security responsibilities
- system/network administrators
Test
- Organizational processes for managing access restrictions to change
- mechanisms supporting and/or implementing access restrictions for change
Related controls
CM-5(7) — Automatic Implementation of Security Safeguards
This enhancement is marked withdrawn in the official OSCAL catalog. Related-control metadata below may identify where its intent was incorporated.
Authoritative sources
Bare Metal Cyber is an independent educational publisher and is not affiliated with or endorsed by NIST. Official control requirements and interpretations remain with NIST and the responsible authorizing organization.