DKDavid Koran& Associates
Home The CMMC Guide Part III · Configuration Management CM.L2-3.4.3
The CMMC Guide · Configuration Management Family

CM.L2-3.4.3  Track and Control Changes

Track, review, approve or disapprove, and log changes to organizational systems.

Family
Configuration ManagementCM, 9 requirements
Point Value
1Lower weight, but not POA&M exempt
POA&M Eligible
YesOne-point requirement, may be deferred
Objectives
FourPer NIST SP 800-171A

1Overview

CM.L2-3.4.3 governs how systems change. It requires that the organization track, review, approve or disapprove, and log changes to its systems, so that changes happen through a deliberate process rather than ad hoc, and so there is a record of what changed and who approved it. It is a one-point requirement and may be deferred on a plan of action.

Uncontrolled change is how a secure configuration quietly becomes an insecure one. A well-meaning administrator opens a port for a vendor, a setting is loosened to make something work, a system is modified under pressure, and each change, unreviewed and unrecorded, erodes the baseline. This control asks the organization to run changes through a process: track them, review them, approve or disapprove them, and log them, so that change is intentional and traceable. It is the discipline that keeps the baseline of 3.4.1 from drifting through everyday modifications.

The requirement · NIST SP 800-171 Rev 2, 3.4.3

Track, review, approve or disapprove, and log changes to organizational systems.

The requirement names four actions that together form change control: track what is changing, review it for impact and appropriateness, approve or disapprove it as a decision, and log it so there is a record. For a small organization this need not be heavy process, but each of the four elements has to be present, so that changes are seen, judged, decided, and recorded rather than made silently.

2The Assessment Objectives

NIST SP 800-171A decomposes 3.4.3 into four objectives, one for each action: track, review, approve or disapprove, and log.

[a]

Changes to the system are tracked. The organization knows what changes are proposed and made.

MeetsChanges are captured in a tracking process, such as a change log or ticketing system.
FailsChanges are made without being recorded anywhere, so they cannot be tracked.
[b]

Changes to the system are reviewed. Proposed changes are examined before or as they are made.

MeetsChanges are reviewed for appropriateness and impact as part of the process.
FailsChanges go straight in with no review.
[c]

Changes to the system are approved or disapproved. A decision is made on each change.

MeetsChanges carry an approval or disapproval decision by an appropriate authority.
FailsNo approval step exists, so anyone changes anything without a decision.
[d]

Changes to the system are logged. There is a record of the changes made.

MeetsChanges are logged with what changed, when, and by whom, retained for reference.
FailsChanges leave no record, so there is no history of what was modified.

The four objectives are the four actions of change control. The common gap is at objectives [b] and [c], review and approval, where changes are tracked and logged but not actually reviewed or decided, so the process records change without governing it. The assessor looks for all four elements, especially a real review and approval step.

3Failure Patterns

The failures are about ad hoc change and process missing one of its four parts.

Change without a process

Where administrators change systems whenever needed with no tracking, review, approval, or log, the baseline erodes invisibly. A defined change process, even a light one, is what the control requires.

Logged but never reviewed

A change log that records what happened but where nothing was reviewed or approved beforehand captures history without governing change, leaving objectives [b] and [c] unmet. Review and approval are what make change control a control rather than a diary.

Approval without a record

Changes approved verbally with no log leave no evidence of what was decided or done, failing objective [d]. The log is what makes the process demonstrable and the history traceable.

Emergency changes outside the process

Urgent changes made outside the process and never brought back into it become permanent unreviewed modifications. A path for emergency changes to be reviewed and logged after the fact keeps them within the control.

The common root
This control fails when change is silent. Each unreviewed, unrecorded modification is small, but together they drift the environment away from its secure baseline, and without tracking, review, approval, and logging there is no way to see it happening or to reconstruct what changed.

4Ownership

This is an IT-owned control, though the review and approval step often involves a change authority beyond the person making the change.

RoleResponsibility for this control
IT and system administratorRuns changes through the tracking, review, approval, and logging process. Owns the change records.
Change authorityReviews and approves or disapproves changes, providing the decision the control requires, separate from the person making the change where practical.
Security or compliance leadConfirms all four elements are present and that changes actually pass through the process.
See also: This control protects the baseline of CM.L2-3.4.1, pairs with the security impact analysis of CM.L2-3.4.4, and connects to the access restrictions for change at CM.L2-3.4.5.

5Tooling

The control is delivered by a change process, which for many organizations is a ticketing or change-log system with a review and approval step.

ObjectivesToolingWhat it provides
[a], [d]Change ticketing or change logTracking and logging of changes with what, when, and by whom.
[b], [c]Review and approval workflowThe review and the approve or disapprove decision on each change.
Emergency pathAfter-the-fact review processA way to bring urgent changes back into review and logging.

The caveat is that the process must include all four actions, not just record-keeping. A change log alone captures history but does not review or decide, so the review and approval steps have to be real. The assessor examines whether changes are tracked, reviewed, decided, and logged, so all four have to be evident in practice.

6Evidence

The satisfied version of 3.4.3 shows changes passing through all four actions.

EvidenceWhat it demonstrates
Change process documentationObjectives [a] through [d]. The defined tracking, review, approval, and logging.
Change records with approvalsObjectives [b], [c]. Evidence changes were reviewed and decided.
Change logObjectives [a], [d]. The record of what changed, when, and by whom.

The evidence should show changes that were tracked, reviewed, approved or disapproved, and logged, with records carrying the approval decisions. Change records that demonstrate all four actions are the clearest demonstration of the control.

A secure baseline erodes one silent change at a time

Uncontrolled changes quietly turn a hardened configuration into an insecure one, and this control asks for the tracking, review, approval, and logging that keep change deliberate. Building a change process that fits a small shop without becoming bureaucracy is part of the onsite readiness work this practice does.

Start CMMC Readiness or call 802-335-2662

7Sources

  1. NIST Special Publication 800-171 Rev 2, Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations, requirement 3.4.3. csrc.nist.gov
  2. NIST Special Publication 800-171A, Assessing Security Requirements for Controlled Unclassified Information, assessment objectives 3.4.3[a] through 3.4.3[d]. csrc.nist.gov
  3. 32 CFR 170.21, Plan of Action and Milestones Requirements, governing which requirements may remain open at a Level 2 assessment. ecfr.gov
← Previous in Configuration Management
CM.L2-3.4.2 · Security Configuration Settings
Next in Configuration Management →
CM.L2-3.4.4 · Security Impact Analysis
About the Author
David W. Koran is a CyberAB Registered Practitioner Advanced and the author of The CMMC Decision, now in its second edition. He works onsite with defense contractors and their counsel, from the first leadership briefing through the pre-assessment review. Reach him at 802-335-2662 or dkoran@davidkoran.com.
Entry CM.L2-3.4.3 · Edition 2026.1 · Last reviewed July 12, 2026