800-53|CM-3

Title

CONFIGURATION CHANGE CONTROL

Description

The organization:

Supplemental

Configuration change controls for organizational information systems involve the systematic proposal, justification, implementation, testing, review, and disposition of changes to the systems, including system upgrades and modifications. Configuration change control includes changes to baseline configurations for components and configuration items of information systems, changes to configuration settings for information technology products (e.g., operating systems, applications, firewalls, routers, and mobile devices), unscheduled/unauthorized changes, and changes to remediate vulnerabilities. Typical processes for managing configuration changes to information systems include, for example, Configuration Control Boards that approve proposed changes to systems. For new development information systems or systems undergoing major upgrades, organizations consider including representatives from development organizations on the Configuration Control Boards. Auditing of changes includes activities before and after changes are made to organizational information systems and the auditing activities required to implement such changes.

Reference Item Details

Related: CA-7,CM-2,CM-4,CM-5,CM-6,CM-9,SA-10,SI-12,SI-2

Category: CONFIGURATION MANAGEMENT

Family: CONFIGURATION MANAGEMENT

Priority: P1

Baseline Impact: MODERATE,HIGH

Audit Items

View all Reference Audit Items

NamePluginAudit Name
1.2.3.7 Set 'Do not apply during periodic background processing' to 'Enabled:FALSE'WindowsCIS Windows 8 L1 v1.0.0
1.2.3.8 Set 'Process even if the Group Policy objects have not changed' to 'Enabled:TRUE'WindowsCIS Windows 8 L1 v1.0.0
1.3.2 Ensure filesystem integrity is regularly checked - aideUnixCIS Red Hat Enterprise Linux 7 STIG v2.0.0 STIG
1.3.2 Ensure filesystem integrity is regularly checked - cronUnixCIS Red Hat Enterprise Linux 7 STIG v2.0.0 STIG
1.3.2 Ensure filesystem integrity is regularly checked - mailUnixCIS Red Hat Enterprise Linux 7 STIG v2.0.0 STIG
1.4.5.1 Ensure 'aaa command accounting' is configured correctlyCiscoCIS Cisco Firewall ASA 9 L1 v4.1.0
1.4.5.2 Ensure 'aaa accounting for SSH' is configured correctlyCiscoCIS Cisco Firewall ASA 9 L1 v4.1.0
1.4.5.3 Ensure 'aaa accounting for Serial console' is configured correctlyCiscoCIS Cisco Firewall ASA 9 L1 v4.1.0
1.4.5.4 Ensure 'aaa accounting for EXEC mode' is configured correctlyCiscoCIS Cisco Firewall ASA 9 L1 v4.1.0
2.5 Ensure Non-Default, Unique Cryptographic Material is in UseUnixCIS MySQL 5.7 Community Linux OS L1 v2.0.0
2.5 Ensure Non-Default, Unique Cryptographic Material is in UseUnixCIS MySQL 5.7 Enterprise Linux OS L1 v2.0.0
2.6 Ensure Non-Default, Unique Cryptographic Material is in UseUnixCIS MySQL 8.0 Community Linux OS L1 v1.0.0
2.6 Ensure Non-Default, Unique Cryptographic Material is in UseUnixCIS MySQL 8.0 Enterprise Linux OS L1 v1.3.0
3.15 Ensure Accept Domain Name over TCP (Zone Transfer) is not enabledCheckPointCIS Check Point Firewall L2 v1.1.0
3.16 Ensure Accept Domain Name over UDP (Queries) is not enabledCheckPointCIS Check Point Firewall L2 v1.1.0
3.18 Ensure Allow bi-directional NAT is enabledCheckPointCIS Check Point Firewall L2 v1.1.0
3.19 Ensure Automatic ARP Configuration NAT is enabledCheckPointCIS Check Point Firewall L2 v1.1.0
4.3 Configure Alerts on all Configuration ChangesCiscoCIS Cisco NX-OS L2 v1.1.0
Big Sur - Configure the System to Notify upon Baseline Configuration ChangesUnixNIST macOS Big Sur v1.4.0 - All Profiles
Catalina - Configure the System to Notify upon Baseline Configuration ChangesUnixNIST macOS Catalina v1.5.0 - All Profiles
Configure registry policy processing - NoBackgroundPolicyWindowsMSCT Windows Server v2004 DC v1.0.0
Configure registry policy processing - NoBackgroundPolicyWindowsMSCT Windows 10 v1507 v1.0.0
Configure registry policy processing - NoBackgroundPolicyWindowsMSCT Windows Server 2016 DC v1.0.0
Configure registry policy processing - NoBackgroundPolicyWindowsMSCT Windows Server v20H2 DC v1.0.0
Configure registry policy processing - NoBackgroundPolicyWindowsMSCT Windows Server v20H2 MS v1.0.0
Configure registry policy processing - NoBackgroundPolicyWindowsMSCT Windows 10 v21H1 v1.0.0
Configure registry policy processing - NoBackgroundPolicyWindowsMSCT Windows 10 v21H2 v1.0.0
Configure registry policy processing - NoBackgroundPolicyWindowsMSCT Windows 11 v22H2 v1.0.0
Configure registry policy processing - NoBackgroundPolicyWindowsMSCT Windows Server 1903 DC v1.19.9
Configure registry policy processing - NoBackgroundPolicyWindowsMSCT Windows Server v1909 MS v1.0.0
Configure registry policy processing - NoBackgroundPolicyWindowsMSCT Windows 10 1809 v1.0.0
Configure registry policy processing - NoBackgroundPolicyWindowsMSCT Windows 10 v2004 v1.0.0
Configure registry policy processing - NoBackgroundPolicyWindowsMSCT MSCT Windows Server 2022 DC v1.0.0
Configure registry policy processing - NoBackgroundPolicyWindowsMSCT Windows 10 1903 v1.19.9
Configure registry policy processing - NoBackgroundPolicyWindowsMSCT Windows 10 v20H2 v1.0.0
Configure registry policy processing - NoBackgroundPolicyWindowsMSCT Windows 10 v22H2 v1.0.0
Configure registry policy processing - NoBackgroundPolicyWindowsMSCT Windows 11 v1.0.0
Configure registry policy processing - NoBackgroundPolicyWindowsMSCT Windows 11 v23H2 v1.0.0
Configure registry policy processing - NoBackgroundPolicyWindowsMSCT Windows Server 1903 MS v1.19.9
Configure registry policy processing - NoBackgroundPolicyWindowsMSCT Windows Server v1909 DC v1.0.0
Configure registry policy processing - NoBackgroundPolicyWindowsMSCT Windows Server v2004 MS v1.0.0
Configure registry policy processing - NoBackgroundPolicyWindowsMSCT Windows Server 2019 DC v1.0.0
Configure registry policy processing - NoBackgroundPolicyWindowsMSCT Windows Server 2019 MS v1.0.0
Configure registry policy processing - NoBackgroundPolicyWindowsMSCT Windows Server 2016 MS v1.0.0
Configure registry policy processing - NoBackgroundPolicyWindowsMSCT Windows Server 2022 v1.0.0
Configure registry policy processing - NoBackgroundPolicyWindowsMSCT Windows 10 1909 v1.0.0
Configure registry policy processing - NoBackgroundPolicyWindowsMSCT Windows 10 1803 v1.0.0
Configure registry policy processing - NoGPOListChangesWindowsMSCT Windows 11 v22H2 v1.0.0
Configure registry policy processing - NoGPOListChangesWindowsMSCT Windows 11 v1.0.0
Configure registry policy processing - NoGPOListChangesWindowsMSCT Windows Server 1903 DC v1.19.9