← Controls / CM

CM-03 Configuration Change Control

Configuration Management

Moderate High

Description

a. Determine and document the types of changes to the system that are configuration-controlled; b. Review proposed configuration-controlled changes to the system and approve or disapprove such changes with explicit consideration for security and privacy impact analyses; c. Document configuration change decisions associated with the system; d. Implement approved configuration-controlled changes to the system; e. Retain records of configuration-controlled changes to the system for [Assignment: organization-defined time period]; f. Monitor and review activities associated with configuration-controlled changes to the system; and g. Coordinate and provide oversight for configuration change control activities through [Assignment: organization-defined configuration change control element] that convenes [Selection (one or more): [Assignment: organization-defined frequency]; when [Assignment: organization-defined configuration change conditions]].

Supplemental Guidance

Configuration change control for organizational systems involves the systematic proposal, justification, implementation, testing, review, and disposition of system changes, including system upgrades and modifications. Configuration change control includes changes to baseline configurations, configuration items of systems, operational procedures, configuration settings for system components, remediate vulnerabilities, and unscheduled or unauthorized changes. Processes for managing configuration changes to systems include Configuration Control Boards or Change Advisory Boards that review and approve proposed changes. For changes that impact privacy risk, the senior agency official for privacy updates privacy impact assessments and system of records notices. For new systems or major upgrades, organizations consider including representatives from the development organizations on the Configuration Control Boards or Change Advisory Boards. Auditing of changes includes activities before and after changes are made to systems and the auditing activities required to implement such changes. See also SA-10.

Enhancements (8)

What NIST adds to this control. Select one to read its statement.

CM-03(01) Automated Documentation, Notification, and Prohibition of Changes High

Use [Assignment: organization-defined automated mechanisms] to: a. Document proposed changes to the system; b. Notify [Assignment: organization-defined approval authorities] of proposed changes to the system and request change approval; c. Highlight proposed changes to the system that have not been approved or disapproved within [Assignment: organization-defined time period]; d. Prohibit changes to the system until designated approvals are received; e. Document all changes to the system; and f. Notify [Assignment: organization-defined personnel] when approved changes to the system are completed.

CM-03(02) Testing, Validation, and Documentation of Changes ModerateHigh

Test, validate, and document changes to the system before finalizing the implementation of the changes.

CM-03(03) Automated Change Implementation

Implement changes to the current system baseline and deploy the updated baseline across the installed base using [Assignment: organization-defined automated mechanisms].

CM-03(04) Security and Privacy Representatives ModerateHigh

Require [Assignment: organization-defined security and privacy representatives] to be members of the [Assignment: organization-defined configuration change control element].

CM-03(05) Automated Security Response

Implement the following security responses automatically if baseline configurations are changed in an unauthorized manner: [Assignment: organization-defined security responses].

CM-03(06) Cryptography Management High

Ensure that cryptographic mechanisms used to provide the following controls are under configuration management: [Assignment: organization-defined controls].

CM-03(07) Review System Changes

Review changes to the system [Assignment: organization-defined frequency] or when [Assignment: organization-defined circumstances] to determine whether unauthorized changes have occurred.

CM-03(08) Prevent or Restrict Configuration Changes

Prevent or restrict changes to the configuration of the system under the following circumstances: [Assignment: organization-defined circumstances].

MITRE ATT&CK Techniques (35)

ATT&CK v16.1

Techniques mitigated by this control, mapped via CTID.

Initial Access 2 Execution 1 Persistence 13 Privilege Escalation 6 Defense Evasion 18 Credential Access 2 Lateral Movement 1 Collection 4 Impact 1
Show all 35 techniques grouped by tactic

Lateral Movement

Compliance Mappings

ISO 27001:2022

6.38.19.3A.8.9A.8.32

ISO 27002:2022

5.378.98.32

COBIT 2019

BAI05BAI06BAI07BAI10

CIS Controls v8

CIS 4CIS 16.7

NIST CSF 2.0

DE.CM-01DE.CM-09ID.RA-07PR.PS-01

SOC 2 TSC

CC3.4CC8.1CC8.1-POF1

PCI DSS v4.0.1

1.2.86.511.6

CSA CCM v4

AIS-06CCC-01CCC-02CCC-03CCC-04CCC-05CCC-07CCC-08CCC-09CEK-05IVS-07UEM-05

CSA AICM v1

AIS-06AIS-09AIS-11CCC-01CCC-02CCC-03CCC-05CCC-07CCC-09CEK-05I&S-07MDS-04MDS-06MDS-11UEM-05

FINOS CCC

CCC-C07

ISO 42001:2023

A.6.2.5

IEC 62443

3-3 SR 3.43-3 SR 7.6

PRA Operational Resilience

SS1/21-11.1

MAS TRM

7

BSI IT-Grundschutz

OPS.1.1.2OPS.1.1.3

ANSSI

Hygiene.34Hygiene.36SecNumCloud.13.2

FINMA Circular 2023/1

IV.A(36)IV.A(37)IV.A(38)IV.A(39)IV.A(40)

OSFI B-13

B-13.2.3

EU GDPR

Art.32(1)(b)Art.32(1)(d)

EU DORA

Art.9(4)(e)

BIO2

5.378.98.32

RBI CSF

Annex1.7ITGRCA.13

FISC Security Guidelines

FISC.O3FISC.O12

HKMA TM-E-1

TME1.3.3TME1.4.1TME1.4.2TME1.4.3

MLPS 2.0

8.1.5.18.1.10.48.1.10.68.1.10.8

DNB Good Practice

DNB.10.1DNB.10.2DNB.10.5DNB.13.2

EU CRA

CRA.I.2cCRA.II.2CRA.II.7CRA.Info.8b

SWIFT CSCF

SWIFT.6.2

SAMA CSF

3.33.5

NCA ECC

2-3

UAE IA

T7T10

CBB TM

TM-5TM-11

Qatar NIA

OSSD

CBUAE

CR-7

CBE CSF

CTO-7CTO-9CTO-12

SA JS2

JS2-7.2JS2-8.5

CBN CSF

Part3.3

BoG CISD

CISD-VI

POPIA

s19

BoM CTRM

3.6

IOSCO Cyber Resilience

PROT-6

BCBS 239

Principle 6

CPMI-IOSCO PFMI

CG.PRPFMI.P17

FFIEC IS

II.C.10

NYDFS 500

500.8

HIPAA Security Rule

§164.316(b)(2)(iii)

ECB CROE

CROE.2.3.4

EBA ICT Guidelines

3.4.43.5(b)3.6.3

SEBI CSCRF

PR.IP

BOT Cyber Resilience

Ch2.1Ch10.1

CMMC 2.0

CM

NERC CIP

CIP-010-4

10 CFR 73.54

RG5.71-B-CM

TSA Pipeline SD

SD-2 Sec D

IEEE 1686-2022

5.4

DOE C2M2 v2.1

ASSET

API 1164

Sec 7

IAEA NSS 17-T

Sec 5.4

PCI PTS v6

BFK

FIPS 140-3

FIPS 140-3 §7.11

PCI HSM

4589

ISAE 3402

Clause 4

Solvency II

EIOPA-ICT-4.8EIOPA-ICT-4.11

Lloyd's Minimum Standards

MS5.1MS8.4

NAIC Insurance Data Security

4-config4E

PRA SS1/23

P3.3P3.4P4.4P5.5

FCA SYSC 13

SYSC 13.7.1SYSC 13.7.4SYSC 13.8.4

HITRUST CSF v11

09.a10.d

FDA 21 CFR Part 11

§11.10(k)

FDA Cybersecurity Guidance

PU-1PU-2SA-3

ISO 27799

12.5

NHS DSPT

NDG-8.2

OWASP MASVS v2.1

MASVS-CODE-2

CCSS v9.0

1.01.31.02.6

Basel SCO60

SCO60.52

BSSC Standards

GSP-14KMS-07NOS-10TIS-08

SEC Custody (Digital Assets)

SEC-CD-07

ISO 17799 (legacy)

10.1.210.2.312.4.112.5.112.5.212.5.3

COBIT 4.1 (legacy)

AI6.1AI6.3DS9.2