Skip to main content

πŸ’Ό CM-5 Access Restrictions for Change (L)(M)(H)

  • Contextual name: πŸ’Ό CM-5 Access Restrictions for Change (L)(M)(H)
  • ID: /frameworks/fedramp-low-security-controls/cm/05
  • Located in: πŸ’Ό Configuration Management

Description​

Define, document, approve, and enforce physical and logical access restrictions associated with changes to the system.

Similar​

  • Sections
    • /frameworks/nist-sp-800-53-r5/cm/05
    • /frameworks/fedramp-high-security-controls/cm/05
  • Internal
    • ID: dec-c-c3c6e693

Similar Sections (Take Policies From)​

SectionSub SectionsInternal RulesPoliciesFlags
πŸ’Ό FedRAMP High Security Controls β†’ πŸ’Ό CM-5 Access Restrictions for Change (L)(M)(H)21517
πŸ’Ό NIST SP 800-53 Revision 5 β†’ πŸ’Ό CM-5 Access Restrictions for Change7

Sub Sections​

SectionSub SectionsInternal RulesPoliciesFlags

Policies (8)​

PolicyLogic CountFlags
πŸ“ AWS Account IAM Access Analyzer is not enabled for all regions 🟒1🟒 x6
πŸ“ AWS IAM Policy allows full administrative privileges 🟒1🟒 x6
πŸ“ AWS RDS Instance Auto Minor Version Upgrade is not enabled 🟠🟒1🟠 x1, 🟒 x6
πŸ“ Azure App Service Authentication is disabled and Basic Authentication is enabled 🟒1🟒 x6
πŸ“ Azure App Service Basic Authentication is enabled 🟒🟒 x3
πŸ“ Azure App Service does not run the latest Java version 🟒🟒 x3
πŸ“ Azure App Service does not run the latest PHP version 🟒🟒 x3
πŸ“ Azure App Service does not run the latest Python version 🟒🟒 x3