PlumbTrackLive demoGRC Risk System

← control library

Access Restrictions for Change CM-5

Configuration Management · Low baseline ✗ Not implemented

Status — program-wide

What references this control

No risks name this control in their Framework field yet.

No policies reference it yet.


Link a risk or policy to this control

Attaching adds CM-5 to the item's Framework field; the ✨ AI button suggests the best match. You can also edit the Framework field on a risk / policy directly.

Source: NIST SP 800-53 Rev.5, Configuration Management family NIST SP 800-53 Rev.5. The baseline shows the lowest SP 800-53B baseline (Low / Moderate / High) this control appears in NIST SP 800-53B.

Control guide — plain-English, per NIST SP 800-53

CM-5 (Access Restrictions for Change) makes sure only the right people can actually make changes. You define, document, approve, and enforce both physical and logical limits on who can alter the system — edit its config files, install software, or change its services. It is a Low-baseline control and the enforcement muscle behind change control: even a well-run approval process fails if anyone can bypass it and edit files directly.

What good looks like

Framework mapping

How to move it toward Implemented