PlumbTrackLive demoGRC Risk System

← control library

Impact Analyses CM-4

Configuration Management · Low baseline ✗ Not implemented

Status — program-wide

What references this control

No risks name this control in their Framework field yet.

No policies reference it yet.


Link a risk or policy to this control

Attaching adds CM-4 to the item's Framework field; the ✨ AI button suggests the best match. You can also edit the Framework field on a risk / policy directly.

Source: NIST SP 800-53 Rev.5, Configuration Management family NIST SP 800-53 Rev.5. The baseline shows the lowest SP 800-53B baseline (Low / Moderate / High) this control appears in NIST SP 800-53B.

Control guide — plain-English, per NIST SP 800-53

CM-4 (Impact Analyses) is the ‘think before you change’ step. Before a change goes in, you analyze what it could do to security and privacy — what it touches, what could break, and what new risk it might add. It is a Low-baseline control, and it feeds the change-control gate: the impact analysis is what an approver reads before saying yes.

What good looks like

Framework mapping

How to move it toward Implemented