CM-3(1): Automated Document / Notification / Prohibition Of Changes
Control Family:
Parent Control:
Threats Addressed:
Baselines:
- High
Next Version:
- NIST Special Publication 800-53 Revision 5:
- CM-3(1): Automated Documentation, Notification, and Prohibition of Changes
Control Statement
The organization employs automated mechanisms to:
- Document proposed changes to the information system;
- Notify [Assignment: organized-defined approval authorities] of proposed changes to the information system and request change approval;
- Highlight proposed changes to the information system that have not been approved or disapproved by [Assignment: organization-defined time period];
- Prohibit changes to the information system until designated approvals are received;
- Document all changes to the information system; and
- Notify [Assignment: organization-defined personnel] when approved changes to the information system are completed.