1Overview
CM.L2-3.4.3 governs how systems change. It requires that the organization track, review, approve or disapprove, and log changes to its systems, so that changes happen through a deliberate process rather than ad hoc, and so there is a record of what changed and who approved it. It is a one-point requirement and may be deferred on a plan of action.
Uncontrolled change is how a secure configuration quietly becomes an insecure one. A well-meaning administrator opens a port for a vendor, a setting is loosened to make something work, a system is modified under pressure, and each change, unreviewed and unrecorded, erodes the baseline. This control asks the organization to run changes through a process: track them, review them, approve or disapprove them, and log them, so that change is intentional and traceable. It is the discipline that keeps the baseline of 3.4.1 from drifting through everyday modifications.
Track, review, approve or disapprove, and log changes to organizational systems.
The requirement names four actions that together form change control: track what is changing, review it for impact and appropriateness, approve or disapprove it as a decision, and log it so there is a record. For a small organization this need not be heavy process, but each of the four elements has to be present, so that changes are seen, judged, decided, and recorded rather than made silently.
2The Assessment Objectives
NIST SP 800-171A decomposes 3.4.3 into four objectives, one for each action: track, review, approve or disapprove, and log.
Changes to the system are tracked. The organization knows what changes are proposed and made.
Changes to the system are reviewed. Proposed changes are examined before or as they are made.
Changes to the system are approved or disapproved. A decision is made on each change.
Changes to the system are logged. There is a record of the changes made.
The four objectives are the four actions of change control. The common gap is at objectives [b] and [c], review and approval, where changes are tracked and logged but not actually reviewed or decided, so the process records change without governing it. The assessor looks for all four elements, especially a real review and approval step.
3Failure Patterns
The failures are about ad hoc change and process missing one of its four parts.
Change without a process
Where administrators change systems whenever needed with no tracking, review, approval, or log, the baseline erodes invisibly. A defined change process, even a light one, is what the control requires.
Logged but never reviewed
A change log that records what happened but where nothing was reviewed or approved beforehand captures history without governing change, leaving objectives [b] and [c] unmet. Review and approval are what make change control a control rather than a diary.
Approval without a record
Changes approved verbally with no log leave no evidence of what was decided or done, failing objective [d]. The log is what makes the process demonstrable and the history traceable.
Emergency changes outside the process
Urgent changes made outside the process and never brought back into it become permanent unreviewed modifications. A path for emergency changes to be reviewed and logged after the fact keeps them within the control.
4Ownership
This is an IT-owned control, though the review and approval step often involves a change authority beyond the person making the change.
| Role | Responsibility for this control |
|---|---|
| IT and system administrator | Runs changes through the tracking, review, approval, and logging process. Owns the change records. |
| Change authority | Reviews and approves or disapproves changes, providing the decision the control requires, separate from the person making the change where practical. |
| Security or compliance lead | Confirms all four elements are present and that changes actually pass through the process. |
5Tooling
The control is delivered by a change process, which for many organizations is a ticketing or change-log system with a review and approval step.
| Objectives | Tooling | What it provides |
|---|---|---|
| [a], [d] | Change ticketing or change log | Tracking and logging of changes with what, when, and by whom. |
| [b], [c] | Review and approval workflow | The review and the approve or disapprove decision on each change. |
| Emergency path | After-the-fact review process | A way to bring urgent changes back into review and logging. |
The caveat is that the process must include all four actions, not just record-keeping. A change log alone captures history but does not review or decide, so the review and approval steps have to be real. The assessor examines whether changes are tracked, reviewed, decided, and logged, so all four have to be evident in practice.
6Evidence
The satisfied version of 3.4.3 shows changes passing through all four actions.
| Evidence | What it demonstrates |
|---|---|
| Change process documentation | Objectives [a] through [d]. The defined tracking, review, approval, and logging. |
| Change records with approvals | Objectives [b], [c]. Evidence changes were reviewed and decided. |
| Change log | Objectives [a], [d]. The record of what changed, when, and by whom. |
The evidence should show changes that were tracked, reviewed, approved or disapproved, and logged, with records carrying the approval decisions. Change records that demonstrate all four actions are the clearest demonstration of the control.
A secure baseline erodes one silent change at a time
Uncontrolled changes quietly turn a hardened configuration into an insecure one, and this control asks for the tracking, review, approval, and logging that keep change deliberate. Building a change process that fits a small shop without becoming bureaucracy is part of the onsite readiness work this practice does.
Start CMMC Readiness or call 802-335-26627Sources
- NIST Special Publication 800-171 Rev 2, Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations, requirement 3.4.3. csrc.nist.gov
- NIST Special Publication 800-171A, Assessing Security Requirements for Controlled Unclassified Information, assessment objectives 3.4.3[a] through 3.4.3[d]. csrc.nist.gov
- 32 CFR 170.21, Plan of Action and Milestones Requirements, governing which requirements may remain open at a Level 2 assessment. ecfr.gov