{"data":{"id":"CM-03","name":"Configuration Change Control","family":"CM","family_name":"Configuration Management","withdrawn":false,"description":"a. Determine and document the types of changes to the system that are configuration-controlled;\nb. Review proposed configuration-controlled changes to the system and approve or disapprove such changes with explicit consideration for security and privacy impact analyses;\nc. Document configuration change decisions associated with the system;\nd. Implement approved configuration-controlled changes to the system;\ne. Retain records of configuration-controlled changes to the system for [Assignment: organization-defined time period];\nf. Monitor and review activities associated with configuration-controlled changes to the system; and\ng. Coordinate and provide oversight for configuration change control activities through [Assignment: organization-defined configuration change control element] that convenes [Selection (one or more): [Assignment: organization-defined frequency]; when [Assignment: organization-defined configuration change conditions]].","supplemental_guidance":"Configuration change control for organizational systems involves the systematic proposal, justification, implementation, testing, review, and disposition of system changes, including system upgrades and modifications. Configuration change control includes changes to baseline configurations, configuration items of systems, operational procedures, configuration settings for system components, remediate vulnerabilities, and unscheduled or unauthorized changes. Processes for managing configuration changes to systems include Configuration Control Boards or Change Advisory Boards that review and approve proposed changes. For changes that impact privacy risk, the senior agency official for privacy updates privacy impact assessments and system of records notices. For new systems or major upgrades, organizations consider including representatives from the development organizations on the Configuration Control Boards or Change Advisory Boards. Auditing of changes includes activities before and after changes are made to systems and the auditing activities required to implement such changes. See also SA-10.","enhancements":[{"id":"CM-03(01)","name":"Automated Documentation, Notification, and Prohibition of Changes","statement":"Use [Assignment: organization-defined automated mechanisms] to:\na. Document proposed changes to the system;\nb. Notify [Assignment: organization-defined approval authorities] of proposed changes to the system and request change approval;\nc. Highlight proposed changes to the system that have not been approved or disapproved within [Assignment: organization-defined time period];\nd. Prohibit changes to the system until designated approvals are received;\ne. Document all changes to the system; and\nf. Notify [Assignment: organization-defined personnel] when approved changes to the system are completed.","baselines":["high"]},{"id":"CM-03(02)","name":"Testing, Validation, and Documentation of Changes","statement":"Test, validate, and document changes to the system before finalizing the implementation of the changes.","baselines":["moderate","high"]},{"id":"CM-03(03)","name":"Automated Change Implementation","statement":"Implement changes to the current system baseline and deploy the updated baseline across the installed base using [Assignment: organization-defined automated mechanisms].","baselines":[]},{"id":"CM-03(04)","name":"Security and Privacy Representatives","statement":"Require [Assignment: organization-defined security and privacy representatives] to be members of the [Assignment: organization-defined configuration change control element].","baselines":["moderate","high"]},{"id":"CM-03(05)","name":"Automated Security Response","statement":"Implement the following security responses automatically if baseline configurations are changed in an unauthorized manner: [Assignment: organization-defined security responses].","baselines":[]},{"id":"CM-03(06)","name":"Cryptography Management","statement":"Ensure that cryptographic mechanisms used to provide the following controls are under configuration management: [Assignment: organization-defined controls].","baselines":["high"]},{"id":"CM-03(07)","name":"Review System Changes","statement":"Review changes to the system [Assignment: organization-defined frequency] or when [Assignment: organization-defined circumstances] to determine whether unauthorized changes have occurred.","baselines":[]},{"id":"CM-03(08)","name":"Prevent or Restrict Configuration Changes","statement":"Prevent or restrict changes to the configuration of the system under the following circumstances: [Assignment: organization-defined circumstances].","baselines":[]}],"baseline_low":false,"baseline_moderate":true,"baseline_high":true,"nist_800_53":{"rev5":{"id":"CM-03","name":"Configuration Change Control","description":"a. Determine and document the types of changes to the system that are configuration-controlled;\nb. Review proposed configuration-controlled changes to the system and approve or disapprove such changes with explicit consideration for security and privacy impact analyses;\nc. Document configuration change decisions associated with the system;\nd. Implement approved configuration-controlled changes to the system;\ne. Retain records of configuration-controlled changes to the system for [Assignment: organization-defined time period];\nf. Monitor and review activities associated with configuration-controlled changes to the system; and\ng. Coordinate and provide oversight for configuration change control activities through [Assignment: organization-defined configuration change control element] that convenes [Selection (one or more): [Assignment: organization-defined frequency]; when [Assignment: organization-defined configuration change conditions]].","discussion":"Configuration change control for organizational systems involves the systematic proposal, justification, implementation, testing, review, and disposition of system changes, including system upgrades and modifications. Configuration change control includes changes to baseline configurations, configuration items of systems, operational procedures, configuration settings for system components, remediate vulnerabilities, and unscheduled or unauthorized changes. Processes for managing configuration changes to systems include Configuration Control Boards or Change Advisory Boards that review and approve proposed changes. For changes that impact privacy risk, the senior agency official for privacy updates privacy impact assessments and system of records notices. For new systems or major upgrades, organizations consider including representatives from the development organizations on the Configuration Control Boards or Change Advisory Boards. Auditing of changes includes activities before and after changes are made to systems and the auditing activities required to implement such changes. See also SA-10.","related_controls":["CA-07","CM-02","CM-04","CM-05","CM-06","CM-09","CM-11","IA-03","MA-02","PE-16","PT-06","RA-08","SA-08","SA-10","SC-28","SC-34","SC-37","SI-02","SI-03","SI-04","SI-07","SI-10","SR-11"],"baseline_low":false,"baseline_moderate":true,"baseline_high":true,"baseline_privacy":false,"new_in_rev5":false,"changes_from_rev4":""}},"compliance_mappings":{"iso_27001_2022":["6.3","8.1","9.3","A.8.9","A.8.32"],"iso_27002_2022":["5.37","8.9","8.32"],"cobit_2019":["BAI05","BAI06","BAI07","BAI10"],"pci_dss_v4":["1.2.8","6.5","11.6"],"nist_csf_2":["DE.CM-01","DE.CM-09","ID.RA-07","PR.PS-01"],"cis_controls_v8":["CIS 4","CIS 16.7"],"soc2_tsc":["CC3.4","CC8.1","CC8.1-POF1"],"finos_ccc":["CCC-C07"],"iso_42001_2023":["A.6.2.5"],"iec_62443":["3-3 SR 3.4","3-3 SR 7.6"],"asd_e8":[],"nis2":[],"apra_cps_234":[],"mas_trm":["7"],"pra_op_resilience":["SS1/21-11.1"],"bsi_grundschutz":["OPS.1.1.2","OPS.1.1.3"],"anssi":["Hygiene.34","Hygiene.36","SecNumCloud.13.2"],"osfi_b13":["B-13.2.3"],"finma_circular":["IV.A(36)","IV.A(37)","IV.A(38)","IV.A(39)","IV.A(40)"],"gdpr":["Art.32(1)(b)","Art.32(1)(d)"],"dora":["Art.9(4)(e)"],"bio2":["5.37","8.9","8.32"],"rbi_csf":["Annex1.7","ITGRCA.13"],"fisc":["FISC.O3","FISC.O12"],"lgpd_bcb":[],"hkma_tme1":["TME1.3.3","TME1.4.1","TME1.4.2","TME1.4.3"],"mlps_2":["8.1.5.1","8.1.10.4","8.1.10.6","8.1.10.8"],"dnb_good_practice":["DNB.10.1","DNB.10.2","DNB.10.5","DNB.13.2"],"cra":["CRA.I.2c","CRA.II.2","CRA.II.7","CRA.Info.8b"],"swift_cscf":["SWIFT.6.2"],"cbb_tm":["TM-5","TM-11"],"cbuae":["CR-7"],"nca_ecc":["2-3"],"qatar_nia":["OS","SD"],"sama_csf":["3.3","3.5"],"uae_ia":["T7","T10"],"bog_cisd":["CISD-VI"],"bom_ctrm":["3.6"],"cbe_csf":["CTO-7","CTO-9","CTO-12"],"cbn_csf":["Part3.3"],"popia":["s19"],"sa_js2":["JS2-7.2","JS2-8.5"],"bcbs_239":["Principle 6"],"bot_cyber":["Ch2.1","Ch10.1"],"cpmi_pfmi":["CG.PR","PFMI.P17"],"eba_ict":["3.4.4","3.5(b)","3.6.3"],"ecb_croe":["CROE.2.3.4"],"ffiec_is":["II.C.10"],"hipaa_sr":["§164.316(b)(2)(iii)"],"iosco_cyber":["PROT-6"],"nydfs_500":["500.8"],"sebi_cscrf":["PR.IP"],"cmmc_2":["CM"],"nerc_cip":["CIP-010-4"],"nrc_73_54":["RG5.71-B-CM"],"tsa_psd":["SD-2 Sec D"],"ieee_1686":["5.4"],"ferc_cip":[],"doe_c2m2":["ASSET"],"api_1164":["Sec 7"],"awia":[],"iaea_nss":["Sec 5.4"],"pci_pts":["B","F","K"],"fips_140":["FIPS 140-3 §7.11"],"cbest":[],"tiber_eu":[],"pci_hsm":["4","5","8","9"],"common_criteria":[],"isae_3402":["Clause 4"],"fca_sysc_13":["SYSC 13.7.1","SYSC 13.7.4","SYSC 13.8.4"],"fda_21_cfr_11":["§11.10(k)"],"fda_cyber":["PU-1","PU-2","SA-3"],"hitrust_csf":["09.a","10.d"],"iso_27799":["12.5"],"lloyds_ms":["MS5.1","MS8.4"],"naic_ds":["4-config","4E"],"nhs_dspt":["NDG-8.2"],"pra_ss1_23":["P3.3","P3.4","P4.4","P5.5"],"solvency_ii":["EIOPA-ICT-4.8","EIOPA-ICT-4.11"],"owasp_masvs_v2":["MASVS-CODE-2"],"csa_ccm_v4":["AIS-06","CCC-01","CCC-02","CCC-03","CCC-04","CCC-05","CCC-07","CCC-08","CCC-09","CEK-05","IVS-07","UEM-05"],"csa_aicm":["AIS-06","AIS-09","AIS-11","CCC-01","CCC-02","CCC-03","CCC-05","CCC-07","CCC-09","CEK-05","I&S-07","MDS-04","MDS-06","MDS-11","UEM-05"],"ccss_v9":["1.01.3","1.02.6"],"mica":[],"basel_sco60":["SCO60.52"],"bssc":["GSP-14","KMS-07","NOS-10","TIS-08"],"sec_custody_digital":["SEC-CD-07"],"dpdpa":[]},"attack_techniques":[{"id":"T1176","name":"Browser Extensions","tactics":["persistence"],"mapping_type":"mitigates","mapping_rationale":"Configuration change control processes that require approval and documentation for browser extension installations prevent adversaries from persisting through unauthorized extensions by enforcing a whitelist of approved add-ons."},{"id":"T1195","name":"Supply Chain Compromise","tactics":["initial-access"],"mapping_type":"mitigates","mapping_rationale":"Change control processes that validate the integrity of software before deployment—including hash verification and code signing validation—detect supply chain compromise by identifying tampered packages during the approval workflow."},{"id":"T1213","name":"Data from Information Repositories","tactics":["collection"],"mapping_type":"mitigates","mapping_rationale":"Configuration change control over information repository access permissions and sharing settings prevents unauthorized data exposure by requiring approval for changes that could widen access to sensitive organizational data."},{"id":"T1495","name":"Firmware Corruption","tactics":["impact"],"mapping_type":"mitigates","mapping_rationale":"Change control over firmware update processes—requiring authorization, integrity verification, and testing before deployment—prevents adversary firmware corruption by ensuring only approved, validated firmware is installed."},{"id":"T1542","name":"Pre-OS Boot","tactics":["defense-evasion","persistence"],"mapping_type":"mitigates","mapping_rationale":"Configuration change control over boot process components—including BIOS, UEFI, and bootloader configurations—prevents pre-OS boot persistence by requiring authorized approval for any changes to system boot infrastructure."},{"id":"T1543","name":"Create or Modify System Process","tactics":["persistence","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Change control over system process configurations—including service creation, daemon installation, and launch agent registration—prevents unauthorized persistence by requiring approval for new system-level processes."},{"id":"T1546","name":"Event Triggered Execution","tactics":["persistence","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Configuration change control over event-triggered execution mechanisms—including registry run keys, WMI subscriptions, and shell configurations—prevents adversary persistence by requiring approval for event handler modifications."},{"id":"T1548","name":"Abuse Elevation Control Mechanism","tactics":["defense-evasion","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Change control over elevation control configurations—including UAC settings, sudoers files, and setuid permissions—prevents privilege escalation by requiring authorized approval for changes to privilege boundary mechanisms."},{"id":"T1553","name":"Subvert Trust Controls","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Configuration change control over trust control settings—including certificate stores, code signing policies, and Gatekeeper configurations—prevents adversary subversion of trust controls through unauthorized trust modifications."},{"id":"T1555","name":"Credentials from Password Stores","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"Change control governing credential store configurations and access policies prevents adversary access to password stores by ensuring modifications to credential management infrastructure require documented authorization."},{"id":"T1601","name":"Modify System Image","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Configuration change control over network device firmware updates—requiring formal approval, integrity verification, and rollback planning—prevents unauthorized system image modifications that could introduce backdoors."},{"id":"T1647","name":"Plist File Modification","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Change control over macOS plist file modifications—particularly in system preference and application configuration directories—prevents adversary defense evasion through unauthorized property list manipulation."},{"id":"T1653","name":"Power Settings","tactics":["persistence"],"mapping_type":"mitigates","mapping_rationale":"Configuration change control requiring approval for power management setting modifications prevents adversaries from altering sleep, hibernate, and wake configurations to maintain persistent system availability."},{"id":"T1666","name":"Modify Cloud Resource Hierarchy","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Change control over cloud resource hierarchy configurations—including organizational units, folder structures, and resource policies—detects and prevents unauthorized modifications that could weaken inherited security controls."},{"id":"T1021.005","name":"VNC","tactics":["lateral-movement"],"mapping_type":"mitigates","mapping_rationale":"Configuration change control over VNC server installations and remote access configurations prevents adversary lateral movement by ensuring VNC deployments require formal approval and follow security standards."},{"id":"T1059.006","name":"Python","tactics":["execution"],"mapping_type":"mitigates","mapping_rationale":"Change control over Python interpreter installations and configurations prevents adversary execution by ensuring Python environments are approved, inventoried, and restricted to authorized development and operations contexts."},{"id":"T1195.003","name":"Compromise Hardware Supply Chain","tactics":["initial-access"],"mapping_type":"mitigates","mapping_rationale":"Configuration change control over hardware procurement and installation—including verification of hardware provenance and integrity—detects hardware supply chain compromise by validating components before deployment."},{"id":"T1213.001","name":"Confluence","tactics":["collection"],"mapping_type":"mitigates","mapping_rationale":"Change control over Confluence space permissions, plugin installations, and integration configurations prevents unauthorized data exposure by requiring approval for access control and functionality changes."},{"id":"T1213.002","name":"Sharepoint","tactics":["collection"],"mapping_type":"mitigates","mapping_rationale":"Configuration change control over SharePoint site permissions, sharing settings, and external access policies prevents unauthorized data collection by requiring approval for access configuration changes."},{"id":"T1213.005","name":"Messaging Applications","tactics":["collection"],"mapping_type":"mitigates","mapping_rationale":"Change control over messaging application integrations, bot installations, and data export configurations prevents adversary data collection by requiring approval for changes that could enable unauthorized message access."},{"id":"T1542.001","name":"System Firmware","tactics":["defense-evasion","persistence"],"mapping_type":"mitigates","mapping_rationale":"Configuration change control over BIOS/UEFI firmware updates—requiring manufacturer signatures and administrative approval—prevents adversary persistence through unauthorized system firmware modifications."},{"id":"T1542.003","name":"Bootkit","tactics":["defense-evasion","persistence"],"mapping_type":"mitigates","mapping_rationale":"Change control over boot sector and bootloader configurations prevents bootkit installation by requiring formal authorization and integrity verification for any modifications to the system boot process."},{"id":"T1542.004","name":"ROMMONkit","tactics":["defense-evasion","persistence"],"mapping_type":"mitigates","mapping_rationale":"Configuration change control over network device ROMMON firmware—requiring authenticated updates and integrity validation—prevents adversary installation of persistent rootkits in router monitor firmware."},{"id":"T1542.005","name":"TFTP Boot","tactics":["defense-evasion","persistence"],"mapping_type":"mitigates","mapping_rationale":"Change control over TFTP boot configurations and network boot image management prevents adversaries from redirecting network boot processes to load compromised operating system images."},{"id":"T1543.002","name":"Systemd Service","tactics":["persistence","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Configuration change control over systemd unit file creation and modification—requiring approval for new services—prevents adversary persistence through unauthorized systemd service registration on Linux systems."},{"id":"T1547.007","name":"Re-opened Applications","tactics":["persistence","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Change control over macOS application re-open configurations and LoginItems prevents adversary persistence by requiring approval for changes to auto-launch application settings."},{"id":"T1547.013","name":"XDG Autostart Entries","tactics":["persistence","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Configuration change control over XDG autostart entries—requiring approval for new .desktop files in autostart directories—prevents adversary persistence through Linux desktop environment auto-launch mechanisms."},{"id":"T1553.006","name":"Code Signing Policy Modification","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Change control over code signing policies—including WDAC, AppLocker, and macOS notarization settings—prevents adversary defense evasion by requiring formal approval for any weakening of code signing enforcement."},{"id":"T1556.008","name":"Network Provider DLL","tactics":["credential-access","defense-evasion","persistence"],"mapping_type":"mitigates","mapping_rationale":"Configuration change control over network provider DLL registrations prevents adversary credential harvesting by requiring approval for changes to authentication-related DLL configurations."},{"id":"T1562.008","name":"Disable or Modify Cloud Logs","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Change control over cloud logging configurations—including CloudTrail, Azure Activity Logs, and GCP Audit Logs—prevents adversary defense evasion by requiring approval for changes to cloud audit infrastructure."},{"id":"T1562.012","name":"Disable or Modify Linux Audit System","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Configuration change control over Linux audit system configurations—including auditd rules and audit daemon settings—prevents adversary defense evasion by requiring formal approval for audit system modifications."},{"id":"T1564.008","name":"Email Hiding Rules","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Change control over email rule configurations—requiring approval for auto-forwarding, auto-deletion, and message routing rules—prevents adversary email hiding through unauthorized inbox rule manipulation."},{"id":"T1578.005","name":"Modify Cloud Compute Configurations","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Configuration change control over cloud compute configurations—including security groups, instance types, and network settings—detects unauthorized modifications that adversaries use for defense evasion."},{"id":"T1601.001","name":"Patch System Image","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Change control requiring formal approval, integrity validation, and testing for network device firmware patches prevents adversary installation of backdoored system image patches on network infrastructure."},{"id":"T1601.002","name":"Downgrade System Image","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Configuration change control preventing unauthorized firmware downgrades—requiring business justification and approval for version changes—blocks adversary attempts to revert to vulnerable system images."}],"metadata":{"last_reviewed":"2026-10-03","review_notes":"2026-10-02: iec_62443 clauses derived through CSF 1.1 from ISA's 62443-3-3 mapping (OLIR entry 195) and NIST's SP 800-53 Rev 5 mapping (OLIR entry 81), which both place them and this control under PR.IP-3, \"Configuration change control processes are in place\". OSA had none. 2026-10-03: iso_27001_2022 8.1, 9.3 added from NIST's SP 800-53 Rev 5 to ISO/IEC 27001:2022 crosswalk (OLIR entry 155), which OSA's mapping now takes as its base. 2026-10-03: nist_csf_2 DE.CM-01 added from NIST's CSF 2.0 to SP 800-53 Rev 5.2.0 crosswalk (OLIR entry 186), which OSA's mapping now takes as its base. 2026-10-03: baselines LMH to -MH, from NIST SP 800-53B Release 5.2.0.","mapping_status":"complete"},"function":"preventative","used_by_patterns":["SP-001","SP-002","SP-004","SP-008","SP-011","SP-012","SP-017","SP-019","SP-021","SP-023","SP-025","SP-026","SP-028","SP-029","SP-030","SP-032","SP-037","SP-038","SP-039","SP-041","SP-044","SP-045","SP-046","SP-047","SP-049","SP-051","SP-052","SP-053","SP-054"]}}