1Overview
CM.L2-3.4.5 controls who can change systems and how. It requires that physical and logical access restrictions associated with changes be defined, documented, approved, and enforced, so that the ability to modify systems is limited to authorized people through controlled means. It is a five-point requirement that cannot be deferred on a plan of action.
Change control decides whether a change should happen; this control decides who is allowed to make it and by what path. If anyone can walk up to a server or log in and reconfigure it, the change process is a formality that the unrestricted can bypass. The requirement asks for restrictions on both the physical access, reaching the hardware, and the logical access, the accounts and permissions that allow modification, and it asks that those restrictions be defined, documented, approved, and enforced. Its five-point weight reflects that unrestricted change access undermines the entire configuration management program.
Define, document, approve, and enforce physical and logical access restrictions associated with changes to organizational systems.
The requirement multiplies two dimensions by four actions. The two dimensions are physical access restrictions, controlling who can physically reach systems to change them, and logical access restrictions, controlling who has the accounts and permissions to make changes. The four actions, define, document, approve, and enforce, apply to each, giving eight assessment objectives. The point is that change access is deliberately restricted, that the restrictions are written down and approved, and that they are actually enforced rather than nominal.
2The Assessment Objectives
NIST SP 800-171A decomposes 3.4.5 into eight objectives: define, document, approve, and enforce, applied to physical restrictions and then to logical restrictions.
Physical access restrictions associated with changes are defined. The organization has decided who may physically reach systems to change them.
Physical access restrictions are documented. Those physical restrictions are written down.
Physical access restrictions are approved. The physical restrictions have been approved by an appropriate authority.
Physical access restrictions are enforced. The physical restrictions are actually applied.
Logical access restrictions associated with changes are defined. The organization has decided who has the accounts and permissions to make changes.
Logical access restrictions are documented. Those logical restrictions are written down.
Logical access restrictions are approved. The logical restrictions have been approved.
Logical access restrictions are enforced. The logical restrictions are actually applied.
The eight objectives apply define, document, approve, and enforce to both physical and logical access. The common gap is at the enforcement objectives, [d] and [h], where restrictions are defined, documented, and approved but not actually enforced, so anyone can still make changes. The assessor looks for restrictions that are enforced in both dimensions, not only described.
3Failure Patterns
The failures are about open change access in one dimension or restrictions that are never enforced.
Open logical change access
Where too many accounts hold the permissions to change systems, logical restriction is missing, and the change process can be bypassed by anyone with those rights. Restricting change permissions to authorized administrators is the logical half of the control.
Unsecured physical access to systems
Where servers and infrastructure sit in an open area anyone can reach, physical change access is unrestricted, and a person can modify hardware directly. A secured area for the systems that matter is the physical half.
Defined but not enforced
Restrictions that are defined, documented, and approved but never enforced leave objectives [d] and [h] unmet, because the real access remains open. Enforcement is what makes the restrictions actual.
One dimension only
Controlling logical access while leaving physical access open, or the reverse, leaves half the control unmet, since a change can be made through whichever path is unrestricted. Both dimensions have to be addressed.
4Ownership
This is an IT-owned control with a physical dimension shared by facilities, and its work spans access permissions and the security of the space around systems.
| Role | Responsibility for this control |
|---|---|
| IT and system administrator | Defines, documents, and enforces the logical restrictions on change permissions. Owns the logical evidence. |
| Facilities and operations | Enforce the physical restrictions on reaching systems, such as a secured server area. |
| Security or compliance lead | Approves the restrictions and confirms both physical and logical are enforced, not just documented. |
5Tooling
The control is delivered by access permissions for the logical dimension and physical security for the physical one, both documented and approved.
| Objectives | Tooling | What it provides |
|---|---|---|
| [a] through [d] | Secured server area, physical access controls | Defined, documented, approved, and enforced physical restriction on reaching systems. |
| [e] through [h] | Role-based permissions, restricted administrative rights | Defined, documented, approved, and enforced logical restriction on change permissions. |
| Documentation | Access restriction policy with approval | The written, approved restrictions covering both dimensions. |
The caveat is that both dimensions must be enforced, not just documented and approved. Restrictions that exist on paper but leave physical or logical access open fail the enforcement objectives, so the secured space and the restricted permissions both have to be real. The assessor examines whether change access is actually limited in both dimensions, so enforcement is where the control is won.
6Evidence
The satisfied version of 3.4.5 shows defined, documented, approved, and enforced restrictions in both dimensions.
| Evidence | What it demonstrates |
|---|---|
| Access restriction policy | Objectives [a], [b], [c], [e], [f], [g]. Defined, documented, and approved restrictions in both dimensions. |
| Physical security configuration | Objective [d]. Enforced physical restriction on reaching systems. |
| Logical permission configuration | Objective [h]. Enforced logical restriction on change permissions. |
The evidence should show restrictions in both dimensions that are defined, documented, approved, and actually enforced. The approved policy paired with enforced physical and logical controls is the clearest demonstration, and because this control cannot sit on a plan of action, the enforcement has to be real at the time of assessment.
Change access should be as narrow as change authority
If anyone can reach systems physically or holds broad change permissions, the change process can be bypassed, and this five-point control asks for both paths to be restricted and enforced. Securing the space around systems and narrowing change permissions is part of the onsite readiness work this practice does, and it is one of the controls that must be met rather than deferred.
Start CMMC Readiness or call 802-335-26627Sources
- NIST Special Publication 800-171 Rev 2, Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations, requirement 3.4.5. csrc.nist.gov
- NIST Special Publication 800-171A, Assessing Security Requirements for Controlled Unclassified Information, assessment objectives 3.4.5[a] through 3.4.5[h]. csrc.nist.gov
- 32 CFR 170.24, CMMC Scoring Methodology, listing CM.L2-3.4.5 among the five-point derived security requirements. ecfr.gov