DKDavid Koran& Associates
Home The CMMC Guide Part III · Configuration Management CM.L2-3.4.5
The CMMC Guide · Configuration Management Family

CM.L2-3.4.5  Access Restrictions for Change

Define, document, approve, and enforce physical and logical access restrictions associated with changes to organizational systems.

Family
Configuration ManagementCM, 9 requirements
Point Value
5Highest weight in the methodology
POA&M Eligible
NoCannot remain open at assessment
Objectives
EightPer NIST SP 800-171A

1Overview

CM.L2-3.4.5 controls who can change systems and how. It requires that physical and logical access restrictions associated with changes be defined, documented, approved, and enforced, so that the ability to modify systems is limited to authorized people through controlled means. It is a five-point requirement that cannot be deferred on a plan of action.

Change control decides whether a change should happen; this control decides who is allowed to make it and by what path. If anyone can walk up to a server or log in and reconfigure it, the change process is a formality that the unrestricted can bypass. The requirement asks for restrictions on both the physical access, reaching the hardware, and the logical access, the accounts and permissions that allow modification, and it asks that those restrictions be defined, documented, approved, and enforced. Its five-point weight reflects that unrestricted change access undermines the entire configuration management program.

The requirement · NIST SP 800-171 Rev 2, 3.4.5

Define, document, approve, and enforce physical and logical access restrictions associated with changes to organizational systems.

The requirement multiplies two dimensions by four actions. The two dimensions are physical access restrictions, controlling who can physically reach systems to change them, and logical access restrictions, controlling who has the accounts and permissions to make changes. The four actions, define, document, approve, and enforce, apply to each, giving eight assessment objectives. The point is that change access is deliberately restricted, that the restrictions are written down and approved, and that they are actually enforced rather than nominal.

2The Assessment Objectives

NIST SP 800-171A decomposes 3.4.5 into eight objectives: define, document, approve, and enforce, applied to physical restrictions and then to logical restrictions.

[a]

Physical access restrictions associated with changes are defined. The organization has decided who may physically reach systems to change them.

MeetsDefined physical restrictions limiting who can reach the hardware to make changes.
FailsAnyone can physically reach systems to change them, with no defined restriction.
[b]

Physical access restrictions are documented. Those physical restrictions are written down.

MeetsThe physical change restrictions are documented.
FailsPhysical restrictions exist only in practice, undocumented.
[c]

Physical access restrictions are approved. The physical restrictions have been approved by an appropriate authority.

MeetsThe documented physical restrictions carry approval.
FailsNo approval exists for the physical restrictions.
[d]

Physical access restrictions are enforced. The physical restrictions are actually applied.

MeetsPhysical access to systems for change is enforced, for example through a secured server area.
FailsRestrictions are documented but not enforced, so physical access is open in practice.
[e]

Logical access restrictions associated with changes are defined. The organization has decided who has the accounts and permissions to make changes.

MeetsDefined logical restrictions limiting change permissions to authorized administrators.
FailsChange permissions are broad and undefined.
[f]

Logical access restrictions are documented. Those logical restrictions are written down.

MeetsThe logical change restrictions are documented.
FailsLogical restrictions are undocumented.
[g]

Logical access restrictions are approved. The logical restrictions have been approved.

MeetsThe documented logical restrictions carry approval.
FailsNo approval exists for the logical restrictions.
[h]

Logical access restrictions are enforced. The logical restrictions are actually applied.

MeetsChange permissions are enforced through access controls, so only authorized people can modify systems.
FailsRestrictions are documented but permissions remain broad in practice.

The eight objectives apply define, document, approve, and enforce to both physical and logical access. The common gap is at the enforcement objectives, [d] and [h], where restrictions are defined, documented, and approved but not actually enforced, so anyone can still make changes. The assessor looks for restrictions that are enforced in both dimensions, not only described.

3Failure Patterns

The failures are about open change access in one dimension or restrictions that are never enforced.

Open logical change access

Where too many accounts hold the permissions to change systems, logical restriction is missing, and the change process can be bypassed by anyone with those rights. Restricting change permissions to authorized administrators is the logical half of the control.

Unsecured physical access to systems

Where servers and infrastructure sit in an open area anyone can reach, physical change access is unrestricted, and a person can modify hardware directly. A secured area for the systems that matter is the physical half.

Defined but not enforced

Restrictions that are defined, documented, and approved but never enforced leave objectives [d] and [h] unmet, because the real access remains open. Enforcement is what makes the restrictions actual.

One dimension only

Controlling logical access while leaving physical access open, or the reverse, leaves half the control unmet, since a change can be made through whichever path is unrestricted. Both dimensions have to be addressed.

The common root
This control fails when change access is broader than change authority. The change process decides what should change, but if anyone can reach systems physically or holds the permissions to modify them, the process can be bypassed, so both the physical and logical paths to change have to be restricted and enforced.

4Ownership

This is an IT-owned control with a physical dimension shared by facilities, and its work spans access permissions and the security of the space around systems.

RoleResponsibility for this control
IT and system administratorDefines, documents, and enforces the logical restrictions on change permissions. Owns the logical evidence.
Facilities and operationsEnforce the physical restrictions on reaching systems, such as a secured server area.
Security or compliance leadApproves the restrictions and confirms both physical and logical are enforced, not just documented.
See also: This control enforces who may act on the change process of CM.L2-3.4.3, draws on the least privilege of AC.L2-3.1.5, and connects to the physical protection family for the physical dimension.

5Tooling

The control is delivered by access permissions for the logical dimension and physical security for the physical one, both documented and approved.

ObjectivesToolingWhat it provides
[a] through [d]Secured server area, physical access controlsDefined, documented, approved, and enforced physical restriction on reaching systems.
[e] through [h]Role-based permissions, restricted administrative rightsDefined, documented, approved, and enforced logical restriction on change permissions.
DocumentationAccess restriction policy with approvalThe written, approved restrictions covering both dimensions.

The caveat is that both dimensions must be enforced, not just documented and approved. Restrictions that exist on paper but leave physical or logical access open fail the enforcement objectives, so the secured space and the restricted permissions both have to be real. The assessor examines whether change access is actually limited in both dimensions, so enforcement is where the control is won.

6Evidence

The satisfied version of 3.4.5 shows defined, documented, approved, and enforced restrictions in both dimensions.

EvidenceWhat it demonstrates
Access restriction policyObjectives [a], [b], [c], [e], [f], [g]. Defined, documented, and approved restrictions in both dimensions.
Physical security configurationObjective [d]. Enforced physical restriction on reaching systems.
Logical permission configurationObjective [h]. Enforced logical restriction on change permissions.

The evidence should show restrictions in both dimensions that are defined, documented, approved, and actually enforced. The approved policy paired with enforced physical and logical controls is the clearest demonstration, and because this control cannot sit on a plan of action, the enforcement has to be real at the time of assessment.

Change access should be as narrow as change authority

If anyone can reach systems physically or holds broad change permissions, the change process can be bypassed, and this five-point control asks for both paths to be restricted and enforced. Securing the space around systems and narrowing change permissions is part of the onsite readiness work this practice does, and it is one of the controls that must be met rather than deferred.

Start CMMC Readiness or call 802-335-2662

7Sources

  1. NIST Special Publication 800-171 Rev 2, Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations, requirement 3.4.5. csrc.nist.gov
  2. NIST Special Publication 800-171A, Assessing Security Requirements for Controlled Unclassified Information, assessment objectives 3.4.5[a] through 3.4.5[h]. csrc.nist.gov
  3. 32 CFR 170.24, CMMC Scoring Methodology, listing CM.L2-3.4.5 among the five-point derived security requirements. ecfr.gov
← Previous in Configuration Management
CM.L2-3.4.4 · Security Impact Analysis
Next in Configuration Management →
CM.L2-3.4.6 · Least Functionality
About the Author
David W. Koran is a CyberAB Registered Practitioner Advanced and the author of The CMMC Decision, now in its second edition. He works onsite with defense contractors and their counsel, from the first leadership briefing through the pre-assessment review. Reach him at 802-335-2662 or dkoran@davidkoran.com.
Entry CM.L2-3.4.5 · Edition 2026.1 · Last reviewed July 12, 2026