3.4.3

  • Requirement

    a. Define the types of changes to the system that are configuration-controlled.
    b. Review proposed configuration-controlled changes to the system, and approve or disapprove such changes with explicit consideration for security impacts.
    c. Implement and document approved configuration-controlled changes to the system.
    d. Monitor and review activities associated with configuration-controlled changes to the system.

  • Discussion

    Configuration change control refers to tracking, reviewing, approving or disapproving, and logging changes to the system. Specifically, it involves the systematic proposal, justification, implementation, testing, review, and disposition of changes to the system, including system upgrades and modifications. Configuration change control includes changes to baseline configurations for system components (e.g., operating systems, applications, firewalls, routers, mobile devices) and configuration items of the system, changes to configuration settings, unscheduled and unauthorized changes, and changes to remediate vulnerabilities. This requirement is related to 03.04.04.

More Info

  • Family

    Configuration Management
  • Related NIST 800-53 ID

    CM-03
  • Reference Documents

    • N/A

NIST 800-171A r3 Assessment Guidance

CMMC Training

Our CMMC Overview Course simplifies CMMC. Enroll so you can make informed decisions!