# CM-03 Configuration Change Control

NIST SP 800-53 control. Family: CM Configuration Management. Function: preventative. Baselines: moderate, high. Mapping licence: CC BY-SA 4.0.

Statement: a. Determine and document the types of changes to the system that are configuration-controlled; b. Review proposed configuration-controlled changes to the system and approve or disapprove such changes with explicit consideration for security and privacy impact analyses; c. Document configuration change decisions associated with the system; d. Implement approved configuration-controlled changes to the system; e. Retain records of configuration-controlled changes to the system for [Assignment: organization-defined time period]; f. Monitor and review activities associated with configuration-controlled changes to the system; and g. Coordinate and provide oversight for configuration change control activities through [Assignment: organization-defined configuration change control element] that convenes [Selection (one or more): [Assignment: organization-defined frequency]; when [Assignment: organization-defined configuration change conditions]].
Guidance: Configuration change control for organizational systems involves the systematic proposal, justification, implementation, testing, review, and disposition of system changes, including system upgrades and modifications. Configuration change control includes changes to baseline configurations, configuration items of systems, operational procedures, configuration settings for system components, remediate vulnerabilities, and unscheduled or unauthorized changes. Processes for managing configuration changes to systems include Configuration Control Boards or Change Advisory Boards that review and approve proposed changes. For changes that impact privacy risk, the senior agency official for privacy updates privacy impact assessments and system of records notices. For new systems or major upgrades, organizations consider including representatives from the development organizations on the Configuration Control Boards or Change Advisory Boards. Auditing of changes includes activities before and after changes are made to systems and the auditing activities required to implement such changes. See also SA-10.

## Enhancements (8)
- CM-03(01) Automated Documentation, Notification, and Prohibition of Changes. Baselines: high
- CM-03(02) Testing, Validation, and Documentation of Changes. Baselines: moderate, high
- CM-03(03) Automated Change Implementation
- CM-03(04) Security and Privacy Representatives. Baselines: moderate, high
- CM-03(05) Automated Security Response
- CM-03(06) Cryptography Management. Baselines: high
- CM-03(07) Review System Changes
- CM-03(08) Prevent or Restrict Configuration Changes
Each enhancement's statement: /api/v1/controls/CM-03?fields=enhancements

## Patterns that use it (28)
- Critical (7): SP-004 SOA Publication and Location Pattern; SP-017 Secure Network Zone Module; SP-023 Industrial Control Systems; SP-028 Secure DevOps Pipeline Pattern; SP-038 Vulnerability Management and Patching; SP-051 Tokenised Asset Security Architecture (draft); SP-054 CBDC and Digital Currency Infrastructure (draft)
- Important (16): SP-001 Client Module; SP-002 Server Module; SP-008 Public Web Server Pattern; SP-011 Cloud Computing Pattern; SP-012 Secure Software Development Lifecycle; SP-025 Advanced Monitoring and Detection; SP-026 PCI Full Environment; SP-030 API Security; SP-032 Modern Authentication; SP-037 Privileged User Management; SP-045 AI Governance and Responsible AI; SP-046 External Attack Surface Management; SP-047 Secure Agentic AI Frameworks; SP-049 AI in Security Operations (draft); SP-052 Decentralised Identity & Verifiable Credentials (draft); SP-053 Zero-Knowledge Proof Architecture (draft)
- Standard (5): SP-019 Secure Ad-Hoc File Exchange Pattern; SP-021 Realtime Collaboration Pattern; SP-029 Zero Trust Architecture; SP-039 Client-Side Encryption and Data Privacy; SP-044 SaaS Identity Lifecycle Management

## Clauses by framework (77 frameworks)
- iso_27001_2022: 6.3, 8.1, 9.3, A.8.9, A.8.32. OSA's own, not in NIST's crosswalk: 6.3
- iso_27002_2022: 5.37, 8.9, 8.32
- cobit_2019: BAI05, BAI06, BAI07, BAI10
- pci_dss_v4: 1.2.8, 6.5, 11.6
- nist_csf_2: DE.CM-01, DE.CM-09, ID.RA-07, PR.PS-01
- cis_controls_v8: CIS 4, CIS 16.7
- soc2_tsc: CC3.4, CC8.1, CC8.1-POF1
- finos_ccc: CCC-C07
- iso_42001_2023: A.6.2.5
- iec_62443: 3-3 SR 3.4, 3-3 SR 7.6
- mas_trm: 7
- pra_op_resilience: SS1/21-11.1
- bsi_grundschutz: OPS.1.1.2, OPS.1.1.3
- anssi: Hygiene.34, Hygiene.36, SecNumCloud.13.2
- osfi_b13: B-13.2.3
- finma_circular: IV.A(36), IV.A(37), IV.A(38), IV.A(39), IV.A(40)
- gdpr: Art.32(1)(b), Art.32(1)(d)
- dora: Art.9(4)(e)
- bio2: 5.37, 8.9, 8.32
- rbi_csf: Annex1.7, ITGRCA.13
- fisc: FISC.O3, FISC.O12
- hkma_tme1: TME1.3.3, TME1.4.1, TME1.4.2, TME1.4.3
- mlps_2: 8.1.5.1, 8.1.10.4, 8.1.10.6, 8.1.10.8
- dnb_good_practice: DNB.10.1, DNB.10.2, DNB.10.5, DNB.13.2
- cra: CRA.I.2c, CRA.II.2, CRA.II.7, CRA.Info.8b
- swift_cscf: SWIFT.6.2
- cbb_tm: TM-5, TM-11
- cbuae: CR-7
- nca_ecc: 2-3
- qatar_nia: OS, SD
- sama_csf: 3.3, 3.5
- uae_ia: T7, T10
- bog_cisd: CISD-VI
- bom_ctrm: 3.6
- cbe_csf: CTO-7, CTO-9, CTO-12
- cbn_csf: Part3.3
- popia: s19
- sa_js2: JS2-7.2, JS2-8.5
- bcbs_239: Principle 6
- bot_cyber: Ch2.1, Ch10.1
- cpmi_pfmi: CG.PR, PFMI.P17
- eba_ict: 3.4.4, 3.5(b), 3.6.3
- ecb_croe: CROE.2.3.4
- ffiec_is: II.C.10
- hipaa_sr: §164.316(b)(2)(iii)
- iosco_cyber: PROT-6
- nydfs_500: 500.8
- sebi_cscrf: PR.IP
- cmmc_2: CM
- nerc_cip: CIP-010-4
- nrc_73_54: RG5.71-B-CM
- tsa_psd: SD-2 Sec D
- ieee_1686: 5.4
- doe_c2m2: ASSET
- api_1164: Sec 7
- iaea_nss: Sec 5.4
- pci_pts: B, F, K
- fips_140: FIPS 140-3 §7.11
- pci_hsm: 4, 5, 8, 9
- isae_3402: Clause 4
- fca_sysc_13: SYSC 13.7.1, SYSC 13.7.4, SYSC 13.8.4
- fda_21_cfr_11: §11.10(k)
- fda_cyber: PU-1, PU-2, SA-3
- hitrust_csf: 09.a, 10.d
- iso_27799: 12.5
- lloyds_ms: MS5.1, MS8.4
- naic_ds: 4-config, 4E
- nhs_dspt: NDG-8.2
- pra_ss1_23: P3.3, P3.4, P4.4, P5.5
- solvency_ii: EIOPA-ICT-4.8, EIOPA-ICT-4.11
- owasp_masvs_v2: MASVS-CODE-2
- csa_ccm_v4: AIS-06, CCC-01, CCC-02, CCC-03, CCC-04, CCC-05, CCC-07, CCC-08, CCC-09, CEK-05, IVS-07, UEM-05
- csa_aicm: AIS-06, AIS-09, AIS-11, CCC-01, CCC-02, CCC-03, CCC-05, CCC-07, CCC-09, CEK-05, I&S-07, MDS-04, MDS-06, MDS-11, UEM-05
- ccss_v9: 1.01.3, 1.02.6
- basel_sco60: SCO60.52
- bssc: GSP-14, KMS-07, NOS-10, TIS-08
- sec_custody_digital: SEC-CD-07
OSA's mapping for iso_27001_2022 and nist_csf_2 takes NIST's published crosswalk as its base. A clause not marked as OSA's own is in that crosswalk.

## More
- This control as JSON, with guidance and ATT&CK techniques: /api/v1/controls/CM-03
- Clauses only: /api/v1/controls/CM-03?fields=mappings
- Page for people: /controls/cm-03/
- Found an error? Open an issue at https://github.com/opensecurityarchitecture/osa-data/issues with the id, what OSA says and what the source says.
