CM-5(1)
-
Requirement
- Enforce access restrictions using [Assignment: organization-defined automated mechanisms]; and
- Automatically generate audit records of the enforcement actions.
-
Discussion
Organizations log system accesses associated with applying configuration changes to ensure that configuration change control is implemented and to support after-the-fact actions should organizations discover any unauthorized changes.
NIST 800-53A Assessment Guidance
CMMC Training
Our CMMC Overview Course simplifies CMMC. Enroll so you can make informed decisions!