NIST SP 800-53 Rev 5
CM - Configuration Management

NIST SP 800-53 Rev 5 NIST800-CM-3: CM-3 Configuration Change Control

a. Determine and document the types of changes to the system that are configuration-controlled; b. Review proposed configuration-controlled changes to the system and approve or disapprove such changes with explicit consideration for security and privacy impact analyses; c. Document configuration change decisions associated with the system; d. Implement approved configuration-controlled changes to the system; e. Retain records of configuration-controlled changes to the system for [Assignment: organization-defined time period]; f. Monitor and review activities associated with configuration-controlled changes to the system; and g. Coordinate and provide oversight for configuration change control activities through [Assignment: organization-defined configuration change control element] that convenes [Selection (one or more): [Assignment: organization-defined frequency]; when [Assignment: organization-defined configuration change conditions]].

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 115 controls across 49 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

PCI DSS 4.0 · 9 controls

  • 1.2.2 1.2.2 Network connection and NSC changes under change control
  • 1.2.7 1.2.7 Six-monthly review of NSC configurations
  • 1.2.8 1.2.8 NSC configuration files secured and consistent
  • 10.3.4 10.3.4 File integrity monitoring on audit logs
  • 11.3.1.3 11.3.1.3 Internal scans after significant change
  • 11.5.2 11.5.2 Change detection on critical files
  • 6.5.1 6.5.1 Change control procedure for production
  • 6.5.2 6.5.2 Confirm PCI DSS controls after significant change
  • 6.5.4 6.5.4 Separate roles between production and pre-production

CIS Controls v8 · 6 controls

  • CIS-12.3 Securely Manage Network Infrastructure
  • CIS-4.1 Establish and Maintain a Secure Configuration Process
  • CIS-4.2 Establish and Maintain a Secure Configuration Process for Network Infrastructure
  • CIS-4.6 Securely Manage Enterprise Assets and Software
  • CIS-7.3 Perform Automated Operating System Patch Management
  • CIS-8.5 Collect Detailed Audit Logs

FedRAMP High · 6 controls

  • CM-2(2) Automation Support for Accuracy and Currency
  • CM-2(3) Retention of Previous Configurations
  • CM-3 Configuration Change Control
  • CM-3(2) Testing, Validation, and Documentation of Changes
  • CM-3(4) Security and Privacy Representatives
  • CM-8(1) Updates During Installation and Removal

FedRAMP Moderate · 6 controls

  • CM-2(2) Automation Support for Accuracy and Currency
  • CM-2(3) Retention of Previous Configurations
  • CM-3 Configuration Change Control
  • CM-3(2) Testing, Validation, and Documentation of Changes
  • CM-3(4) Security and Privacy Representatives
  • CM-8(1) Updates During Installation and Removal

C5 (Germany) · 4 controls

  • C5-AM-03 Commissioning of Hardware
  • C5-DEV-03 Policies for changes to information systems
  • C5-DEV-08 Version Control
  • C5-DEV-09 Approvals for provision in the production environment

ISO 22301:2019 · 4 controls

  • 6.3 Planning changes to the business continuity management system
  • 7.5.3 Control of documented information
  • 8.1 Operational planning and control
  • 9.3.1 General

NIST SP 800-128 · 4 controls

  • AM-2 Use only approved services
  • ASBv3-PV-4 Audit and enforce secure configurations for compute resources
  • DS-6 Enforce security of workload throughout DevOps lifecycle

ISO/IEC 42001:2023 · 3 controls

  • 7.5.2 Creating and updating documented information
  • 8.3 AI risk treatment
  • A.6 AI system life cycle
  • NIST-CSF-ID.AM-08 Systems, hardware, software, services, and data are managed throughout their life cycles
  • NIST-CSF-ID.RA-07 Changes and exceptions are managed, assessed for risk impact, recorded, and tracked
  • NIST-CSF-PR.PS-01 Configuration management practices are established and applied

NIST SP 800-218 · 3 controls

SOC 2 · 3 controls

  • SOC2-CC3.4 CC3.4 Identifying and assessing significant changes (COSO principle 9)
  • SOC2-CC5.2 CC5.2 General controls over technology (COSO principle 11)
  • SOC2-CC8.1 CC8.1 Managing changes to procedures, software, data and infrastructure
  • SEC01-BP06 Automate deployment of standard security controls
  • SEC11-BP06 Deploy software programmatically

EU AI Act · 2 controls

  • IEC62304-8.2 Change Control
  • IEC62304-9.4 Use Change Control Process

ISO 27001:2022 · 2 controls

  • 8.32 Change management
  • 8.9 Configuration management

ISO 27002:2022 · 2 controls

  • 8.32 Change management
  • 8.9 Configuration management
  • NISTSP82-5 OT Configuration Management, Patching, Vulnerability Management, and Malware Protection
  • NISTSP82-6 OT Audit, Monitoring, Anomaly Detection, and OT-Specific SOC

SASB Standards · 2 controls

  • SASB-1 Business Model + Innovation (BMI)
  • SASB-BMI-5 Physical Impacts of Climate Change
  • SSAE18-CC3.4 CC3.4 - COSO Principle 9: Change Management
  • SSAE18-CC8.1 CC8.1 - Infrastructure and Software Change Management
  • ANSSI-HYG-34 Define an Update Policy for Information System Components

API 1164 · 1 control

  • API1164-23 Change management procedures
  • Clause 10 Change and configuration management
  • AESCSF-ACM-3 Change management

BSI IT-Grundschutz · 1 control

  • BSI-24 Configuration change control

CMMC 2.0 · 1 control

  • FTC-Safeguards-9-Elements 9 Safeguard Elements - Access, Inventory, Encryption, Secure-Dev, MFA, Disposal, Change-Mgmt, Monitoring, Pen-Test (16 CFR 314.4(c))

IEC 62443 · 1 control

  • IEC62443-23 Change management procedures
  • ISO-26262-8-8 Change management

ISO 27701:2019 · 1 control

  • 6.11 Systems acquisition, development and maintenance

ISO 30401 · 1 control

  • ISO30401-18 Innovation and change management
  • ISO20000-06 Change management processes

ISO/IEC 27019:2024 · 1 control

  • ISO27019-23 Change management procedures

ITIL 4 · 1 control

  • ITIL4-06 Change management processes
  • NISTPF-8 Protect-P Information Protection Processes (PR.PO-P)

NIST SP 1800-32 · 1 control

NIST SP 800-172 · 1 control

  • 3.1.1e Dual Authorization for Sensitive System Operations

NIST SP 800-190 · 1 control

  • CM-3 CM-3 Configuration Change Control
  • CM-3 CM-3 Configuration Change Control
  • NRFCS-1 Retail Cybersecurity Governance, Policy, and Regulatory Change Management

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in CM - Configuration Management

You are reading one control. How much of NIST SP 800-53 Rev 5 have you already done?

NIST SP 800-53 Rev 5 NIST800-CM-3 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of NIST SP 800-53 Rev 5 your existing evidence covers. Hold ISO 27001:2022 and 163 of 1014 NIST SP 800-53 Rev 5 controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 342 were rejected on the ISO 27001:2022 pair alone.

Query this from an agent

The graph holds this control, the 115 it maps to, and the evidence behind each claim, over MCP and REST.