CM-03 Configuration Change Control
Configuration Management
Description
a. Determine and document the types of changes to the system that are configuration-controlled; b. Review proposed configuration-controlled changes to the system and approve or disapprove such changes with explicit consideration for security and privacy impact analyses; c. Document configuration change decisions associated with the system; d. Implement approved configuration-controlled changes to the system; e. Retain records of configuration-controlled changes to the system for [Assignment: organization-defined time period]; f. Monitor and review activities associated with configuration-controlled changes to the system; and g. Coordinate and provide oversight for configuration change control activities through [Assignment: organization-defined configuration change control element] that convenes [Selection (one or more): [Assignment: organization-defined frequency]; when [Assignment: organization-defined configuration change conditions]].
Supplemental Guidance
Configuration change control for organizational systems involves the systematic proposal, justification, implementation, testing, review, and disposition of system changes, including system upgrades and modifications. Configuration change control includes changes to baseline configurations, configuration items of systems, operational procedures, configuration settings for system components, remediate vulnerabilities, and unscheduled or unauthorized changes. Processes for managing configuration changes to systems include Configuration Control Boards or Change Advisory Boards that review and approve proposed changes. For changes that impact privacy risk, the senior agency official for privacy updates privacy impact assessments and system of records notices. For new systems or major upgrades, organizations consider including representatives from the development organizations on the Configuration Control Boards or Change Advisory Boards. Auditing of changes includes activities before and after changes are made to systems and the auditing activities required to implement such changes. See also SA-10.
Enhancements (8)
What NIST adds to this control. Select one to read its statement.
CM-03(01) Automated Documentation, Notification, and Prohibition of Changes High
Use [Assignment: organization-defined automated mechanisms] to: a. Document proposed changes to the system; b. Notify [Assignment: organization-defined approval authorities] of proposed changes to the system and request change approval; c. Highlight proposed changes to the system that have not been approved or disapproved within [Assignment: organization-defined time period]; d. Prohibit changes to the system until designated approvals are received; e. Document all changes to the system; and f. Notify [Assignment: organization-defined personnel] when approved changes to the system are completed.
CM-03(02) Testing, Validation, and Documentation of Changes ModerateHigh
Test, validate, and document changes to the system before finalizing the implementation of the changes.
CM-03(03) Automated Change Implementation
Implement changes to the current system baseline and deploy the updated baseline across the installed base using [Assignment: organization-defined automated mechanisms].
CM-03(04) Security and Privacy Representatives ModerateHigh
Require [Assignment: organization-defined security and privacy representatives] to be members of the [Assignment: organization-defined configuration change control element].
CM-03(05) Automated Security Response
Implement the following security responses automatically if baseline configurations are changed in an unauthorized manner: [Assignment: organization-defined security responses].
CM-03(06) Cryptography Management High
Ensure that cryptographic mechanisms used to provide the following controls are under configuration management: [Assignment: organization-defined controls].
CM-03(07) Review System Changes
Review changes to the system [Assignment: organization-defined frequency] or when [Assignment: organization-defined circumstances] to determine whether unauthorized changes have occurred.
CM-03(08) Prevent or Restrict Configuration Changes
Prevent or restrict changes to the configuration of the system under the following circumstances: [Assignment: organization-defined circumstances].
Patterns that use this control (28)
Grouped by the emphasis each pattern gives it.
Critical (7)
- SP-004 SOA Publication and Location Pattern
- SP-017 Secure Network Zone Module
- SP-023 Industrial Control Systems
- SP-028 Secure DevOps Pipeline Pattern
- SP-038 Vulnerability Management and Patching
- SP-051 Tokenised Asset Security Architecture (draft)
- SP-054 CBDC and Digital Currency Infrastructure (draft)
Important (16)
- SP-001 Client Module
- SP-002 Server Module
- SP-008 Public Web Server Pattern
- SP-011 Cloud Computing Pattern
- SP-012 Secure Software Development Lifecycle
- SP-025 Advanced Monitoring and Detection
- SP-026 PCI Full Environment
- SP-030 API Security
- SP-032 Modern Authentication
- SP-037 Privileged User Management
- SP-045 AI Governance and Responsible AI
- SP-046 External Attack Surface Management
- SP-047 Secure Agentic AI Frameworks
- SP-049 AI in Security Operations (draft)
- SP-052 Decentralised Identity & Verifiable Credentials (draft)
- SP-053 Zero-Knowledge Proof Architecture (draft)
MITRE ATT&CK Techniques (35)
ATT&CK v16.1Techniques mitigated by this control, mapped via CTID.