Skip to main content

💼 CM-5 Access Restrictions for Change (L)(M)(H)

  • ID: /frameworks/fedramp-moderate-security-controls/cm/05

Description

Define, document, approve, and enforce physical and logical access restrictions associated with changes to the system.

Similar

  • Sections
    • /frameworks/fedramp-high-security-controls/cm/05
  • Internal
    • ID: dec-c-c3c6e693

Similar Sections (Take Policies From)

SectionSub SectionsInternal RulesPoliciesFlagsCompliance
💼 FedRAMP High Security Controls → 💼 CM-5 Access Restrictions for Change (L)(M)(H)21416no data

Sub Sections

SectionSub SectionsInternal RulesPoliciesFlagsCompliance
💼 CM-5(1) Automated Access Enforcement and Audit Records (M)(H)8no data
💼 CM-5(5) Privilege Limitation for Production and Operation (M)(H)1no data

Policies (8)

PolicyLogic CountFlagsCompliance
🛡️ AWS Account IAM Access Analyzer is not enabled for all regions🟢1🟢 x6no data
🛡️ AWS IAM Policy allows full administrative privileges🟢1🟢 x6no data
🛡️ AWS RDS Instance Auto Minor Version Upgrade is not enabled🟠🟢1🟠 x1, 🟢 x6no data
🛡️ Azure App Service Authentication is disabled and Basic Authentication is enabled🟢1🟢 x6no data
🛡️ Azure App Service Basic Authentication is enabled🟢⚪🟢 x2, ⚪ x1no data
🛡️ Azure App Service does not run the latest Java version🟢⚪🟢 x2, ⚪ x1no data
🛡️ Azure App Service does not run the latest PHP version🟢⚪🟢 x2, ⚪ x1no data
🛡️ Azure App Service does not run the latest Python version🟢⚪🟢 x2, ⚪ x1no data