NIST Special Publication 800-171 Revision 2
Date Published: January 28th, 2021
Withdrawn on May 14, 2024. Superseded by SP 800-171 Rev. 3
Author(s): Ron Ross (NIST), Victoria Pillitteri (NIST), Kelley Dempsey (NIST), Mark Riddle (NARA), Gary Guissanie (IDA)
Note: A Class Deviation is in effect as of May 2, 2024 (DEVIATION 2024O0013). The deviation clause requires contractors, who are subject to 252.204-7012, to comply with National Institute of Standards and Technology (NIST) Special Publication (SP) 800-171 Revision 2, instead of the version of NIST SP 800-171 in effect at the time the solicitation is issued or as authorized by the contracting officer. Click Here
3.4.5 Define, document, approve, and enforce physical and logical access restrictions associated with changes to organizational systems.
Control Family: Configuration Management
Control Type: Derived
SPRS Value: 5
SPRS Supplemental Guidance: N/A
CMMC Level(s): CM.L2-3.4.5
Top Ten Failed Requirement: No
DIBCAC HIGH Failure Rate (OTS):
65th of 110
Referenced in:
DFARS 252.204-7012
Derived From: NIST SP 800-53r4
CM-5
NIST Supplemental Guidance:
[SP 800-128]
CSF v1.1:
PR.IP-3
NIST SP 800-171r2 Control 3.4.5 → MITRE ATT&CK 14.1
Summary
- Total mappings: 147
- Families: 1
- Outer ring: Technique ID + name
- MITRE ATT&CK version: 14.1
Family counts
- Access Restrictions For Change: 147 techniques
Usage notes
- Click a family or technique to zoom in.
- Click the center to zoom back out.
- Hover to view technique details.
Discussion:
Any changes to the hardware, software, or firmware components of systems can potentially have significant effects on the overall security of the systems. Therefore, organizations permit only qualified and authorized individuals to access systems for purposes of initiating changes, including upgrades and modifications.
Access restrictions for change also include software libraries. Access restrictions include physical and logical access control requirements, workflow automation, media libraries, abstract layers (e.g., changes implemented into external interfaces rather than directly into systems), and change windows (e.g., changes occur only during certain specified times). In addition to security concerns, commonly-accepted due diligence for configuration management includes access restrictions as an essential part in ensuring the ability to effectively manage the configuration.
[SP 800-128] provides guidance on configuration change control.
Determining Statements (NIST SP 800-171Ar2)
3.4.5[a] physical access restrictions associated with changes to the system are defined.
3.4.5[b] physical access restrictions associated with changes to the system are
documented.
3.4.5[c] physical access restrictions associated with changes to the system are
approved.
3.4.5[d] physical access restrictions associated with changes to the system are
enforced.
3.4.5[e] logical access restrictions associated with changes to the system are defined.
3.4.5[f] logical access restrictions associated with changes to the system are
documented.
3.4.5[g] logical access restrictions associated with changes to the system are approved.
3.4.5[h] logical access restrictions associated with changes to the system are enforced.
Assessors are instructed to-
Examine: [SELECT FROM: Configuration management policy; procedures addressing access restrictions for changes to the system; system security plan; configuration management plan; system design documentation; system architecture and configuration documentation; system configuration settings and associated documentation; logical access approvals; physical access approvals; access credentials; change control records; system audit logs and records; other relevant documents or records].
Interview: [SELECT FROM: Personnel with logical access control responsibilities; personnel with physical access control responsibilities; personnel with information security responsibilities; system or network administrators].
Test: [SELECT FROM: Organizational processes for managing access restrictions associated with changes to the system; mechanisms supporting, implementing, and enforcing access restrictions associated with changes to the system].
FURTHER DISCUSSION
N Define, identify, and document qualified individuals authorized to make physical and logical changes to the organization’s hardware, software, software libraries, or firmware components. Control of configuration management activities may involve:
physical access control that prohibits unauthorized users from gaining physical access to an asset (e.g., requiring a special key card to enter a server room);
logical access control that prevents unauthorized users from logging onto a system to make configuration changes (e.g., requiring specific credentials for modifying configuration settings, patching software, or updating software libraries);
workflow automation in which configuration management workflow rules define human tasks and data or files are routed between people authorized to do configuration management based on pre-defined business rules (e.g., passing an electronic form to a manager requesting approval of configuration change made by an authorized employee);
an abstraction layer for configuration management that requires changes be made from an external system through constrained interface (e.g., software updates can only be made from a patch management system with a specific IP address); and
utilization of a configuration management change window (e.g., software updates are only allowed between 8:00 AM and 10:00 AM or between 6:00 PM and 8:00 PM).
Example
Your datacenter requires expanded storage capacity in a server. The change has been approved, and security is planning to allow an external technician to access the building at a specific date and time under the supervision of a manager [a,b,c,d]. A system administrator creates a temporary privileged account that can be used to log into the server’s operating system and update storage settings [e,f,g]. On the appointed day, the technician is escorted into the datacenter, upgrades the hardware, expands the storage in the operating system (OS), and departs. The manager verifies the upgrade and disables the privileged account [h].
Potential Assessment Considerations
Are only employees who are approved to make physical or logical changes on systems allowed to do so [a,d,e,h]?
Are authorized personnel approved and documented by the service owner and IT security [a,e]?
Does all change documentation include the name of the authorized employee making the change [b,d,f,h]?
ISO/IEC 27001:2013
A.9.2.3 Management of privileged access rights
A.9.4.5 Access control to program source code
A.12.1.2 Change management
A.12.1.4 Separation of development, testing, and operational environments
A.12.5.1 Installation of software on operational systems
NIST SP 800-171r2 Control 3.4.5 → MITRE ATT&CK
Total Mappings
Families
Control
Access Restrictions for Change 147 techniques
- T1003OS Credential Dumping
- T1003.001LSASS Memory
- T1003.002Security Account Manager
- T1003.003NTDS
- T1003.004LSA Secrets
- T1003.005Cached Domain Credentials
- T1003.006DCSync
- T1003.007Proc Filesystem
- T1003.008/etc/passwd and /etc/shadow
- T1021Remote Services
- T1021.001Remote Desktop Protocol
- T1021.002SMB/Windows Admin Shares
- T1021.003Distributed Component Object Model
- T1021.004SSH
- T1021.005VNC
- T1021.006Windows Remote Management
- T1047Windows Management Instrumentation
- T1053Scheduled Task/Job
- T1053.002At (Windows)
- T1053.003Cron
- T1053.005Scheduled Task
- T1053.006Systemd Timers
- T1053.007Container Orchestration Job
- T1055Process Injection
- T1055.008Ptrace System Calls
- T1056.003Web Portal Capture
- T1059Command and Scripting Interpreter
- T1059.001PowerShell
- T1059.006Python
- T1059.008Network Device CLI
- T1072Software Deployment Tools
- T1078Valid Accounts
- T1078.002Domain Accounts
- T1078.003Local Accounts
- T1078.004Cloud Accounts
- T1098Account Manipulation
- T1098.001Additional Cloud Credentials
- T1098.002Exchange Email Delegate Permissions
- T1098.003Add Office 365 Global Administrator Role
- T1098.004SSH Authorized Keys
- T1098.005Device Registration
- T1134Access Token Manipulation
- T1134.001Token Impersonation/Theft
- T1134.002Create Process with Token
- T1134.003Make and Impersonate Token
- T1136Create Account
- T1136.001Local Account
- T1136.002Domain Account
- T1136.003Cloud Account
- T1137.002Office Test
- T1176Browser Extensions
- T1185Browser Session Hijacking
- T1190Exploit Public-Facing Application
- T1195.003Compromise Hardware Supply Chain
- T1197BITS Jobs
- T1210Exploitation of Remote Services
- T1213Data from Information Repositories
- T1213.001Confluence
- T1213.002Sharepoint
- T1218Signed Binary Proxy Execution
- T1218.007Msiexec
- T1222File and Directory Permissions Modification
- T1222.001Windows File and Directory Permissions Modification
- T1222.002Linux and Mac File and Directory Permissions Modification
- T1484Domain Policy Modification
- T1489Service Stop
- T1495Firmware Corruption
- T1505Server Software Component
- T1505.002Transport Agent
- T1525Implant Internal Image
- T1528Steal Application Access Token
- T1530Data from Cloud Storage Object
- T1537Transfer Data to Cloud Account
- T1542Pre-OS Boot
- T1542.001System Firmware
- T1542.003Bootkit
- T1542.004ROMMONkit
- T1542.005TFTP Boot
- T1543Create or Modify System Process
- T1543.001Launch Agent
- T1543.002Systemd Service
- T1543.003Windows Service
- T1543.004Launch Daemon
- T1546.003Windows Management Instrumentation Event Subscription
- T1546.016Installer Packages
- T1547.003Time Providers
- T1547.004Winlogon Helper DLL
- T1547.006Kernel Modules and Extensions
- T1547.007Re-opened Applications
- T1547.009Shortcut Modification
- T1547.012Print Processors
- T1547.013XDG Autostart Entries
- T1548Abuse Elevation Control Mechanism
- T1548.002Bypass User Account Control
- T1548.003Sudo and Sudo Caching
- T1550Use Alternate Authentication Material
- T1550.002Pass the Hash
- T1550.003Pass the Ticket
- T1552Unsecured Credentials
- T1552.002Credentials in Registry
- T1552.007Container API
- T1553Subvert Trust Controls
- T1553.006Code Signing Policy Modification
- T1556Modify Authentication Process
- T1556.001Domain Controller Authentication
- T1556.003Pluggable Authentication Modules
- T1556.004Network Device Authentication
- T1558Steal or Forge Kerberos Tickets
- T1558.001Golden Ticket
- T1558.002Silver Ticket
- T1558.003Kerberoasting
- T1559Inter-Process Communication
- T1559.001Component Object Model
- T1559.003XPC Services
- T1562Impair Defenses
- T1562.001Disable or Modify Tools
- T1562.002Disable Windows Event Logging
- T1562.004Disable or Modify System Firewall
- T1562.006Indicator Blocking
- T1562.007Disable or Modify Cloud Firewall
- T1562.008Disable Cloud Logs
- T1562.009Safe Mode Boot
- T1563Remote Service Session Hijacking
- T1563.001SSH Hijacking
- T1563.002RDP Hijacking
- T1564.008Email Hiding Rules
- T1569System Services
- T1569.001Launchctl
- T1569.002Service Execution
- T1574Hijack Execution Flow
- T1574.005Executable Installer File Permissions Weakness
- T1574.010Services File Permissions Weakness
- T1574.011Services Registry Permissions Weakness
- T1574.012COR_PROFILER
- T1578Modify Cloud Compute Infrastructure
- T1578.001Create Snapshot
- T1578.002Create Cloud Instance
- T1578.003Delete Cloud Instance
- T1599Network Boundary Bridging
- T1599.001Network Address Translation Traversal
- T1601Modify System Image
- T1601.001Patch System Image
- T1601.002Downgrade System Image
- T1611Escape to Host
- T1619Cloud Storage Object Discovery
- T1621Multi-Factor Authentication Request Generation
- T1647Plist File Modification