03.04.05
Control Familly: Configuration Management
SPRS: N/A
Top Ten Failed Requirement: N/A
Supporting Publications:
FIPS 140-3 [38]
FIPS 180-4 [39]
SP 800-128 [41]
Referenced in: N/A
Control Type: N/A
CPCSC Level 2: 03.04.05
CMMC Level(s): N/A
Derived From: NIST SP 800-53r5
CM-05
Access Restrictions for Change Define, document, approve, and enforce physical and logical access restrictions associated with changes to the system.
Discussion:
Changes to the hardware, software, or firmware components of the system or the operational procedures related to the system can have potentially significant effects on the security of the system. Therefore, organizations permit only qualified and authorized individuals to access the system for the purpose of initiating changes. Access restrictions include physical and logical access controls, software libraries, workflow automation, media libraries, abstract layers (i.e., changes implemented into external interfaces rather than directly into the system), and change windows (i.e., changes occur only during specified times).
Assessment Methods and Objectives
Examine [SELECT FROM: configuration management policy and procedures; procedures for access restrictions for system changes; configuration management plan; system design documentation; system architecture; system configuration settings; logical access approvals; physical access approvals; access credentials; change control records; system audit records; system security plan; other relevant documents or records]
Interview [SELECT FROM: personnel with logical access control responsibilities; personnel with physical access control responsibilities; personnel with information security responsibilities; system administrators]
Test [SELECT FROM: processes for managing access restrictions for system changes; mechanisms for supporting, implementing, or enforcing access restrictions associated with system changes]
NIST SP 800-171A r3 Determining Statements Determine if:
A.03.04.05[01]: physical access restrictions associated with changes to the system are defined and documented.
A.03.04.05[02]: physical access restrictions associated with changes to the system are approved.
A.03.04.05[03]: physical access restrictions associated with changes to the system are enforced.
A.03.04.05[04]: logical access restrictions associated with changes to the system are defined and documented.
A.03.04.05[05]: logical access restrictions associated with changes to the system are approved.
A.03.04.05[06]: logical access restrictions associated with changes to the system are enforced.