Skip to main content

πŸ’Ό CM-5 ACCESS RESTRICTIONS FOR CHANGE

  • Contextual name: πŸ’Ό CM-5 ACCESS RESTRICTIONS FOR CHANGE
  • ID: /frameworks/nist-sp-800-53-r4/cm/05
  • Located in: πŸ’Ό CM CONFIGURATION MANAGEMENT

Description​

The organization defines, documents, approves, and enforces physical and logical access restrictions associated with changes to the information system.

Similar​

  • Internal
    • ID: dec-c-faa17b7e

Similar Sections (Give Policies To)​

SectionSub SectionsInternal RulesPoliciesFlags
πŸ’Ό NIST CSF v1.1 β†’ πŸ’Ό PR.IP-1: A baseline configuration of information technology/industrial control systems is created and maintained incorporating security principles (e.g. concept of least functionality)414

Sub Sections​

SectionSub SectionsInternal RulesPoliciesFlags
πŸ’Ό CM-5 (1) AUTOMATED ACCESS ENFORCEMENT _ AUDITING
πŸ’Ό CM-5 (2) REVIEW SYSTEM CHANGES
πŸ’Ό CM-5 (3) SIGNED COMPONENTS
πŸ’Ό CM-5 (4) DUAL AUTHORIZATION
πŸ’Ό CM-5 (5) LIMIT PRODUCTION _ OPERATIONAL PRIVILEGES
πŸ’Ό CM-5 (6) LIMIT LIBRARY PRIVILEGES
πŸ’Ό CM-5 (7) AUTOMATIC IMPLEMENTATION OF SECURITY SAFEGUARDS