# CM-05 Access Restrictions for Change

NIST SP 800-53 control. Family: CM Configuration Management. Function: preventative. Baselines: low, moderate, high. Mapping licence: CC BY-SA 4.0.

Statement: Define, document, approve, and enforce physical and logical access restrictions associated with changes to the system.
Guidance: Changes to the hardware, software, or firmware components of systems or the operational procedures related to the system can potentially have significant effects on the security of the systems or individuals’ privacy. Therefore, organizations permit only qualified and authorized individuals to access systems for purposes of initiating changes. Access restrictions include physical and logical access controls (see AC-03 and PE-03), software libraries, workflow automation, media libraries, abstract layers (i.e., changes implemented into external interfaces rather than directly into systems), and change windows (i.e., changes occur only during specified times).

## Enhancements (4)
- CM-05(01) Automated Access Enforcement and Audit Records. Baselines: high
- CM-05(04) Dual Authorization
- CM-05(05) Privilege Limitation for Production and Operation
- CM-05(06) Limit Library Privileges
Withdrawn by NIST: CM-05(02) (now in CM-03(07)); CM-05(03) (now in CM-14); CM-05(07) (now in SI-07).
Each enhancement's statement: /api/v1/controls/CM-05?fields=enhancements

## Patterns that use it (8)
- Important (8): SP-001 Client Module; SP-002 Server Module; SP-008 Public Web Server Pattern; SP-011 Cloud Computing Pattern; SP-023 Industrial Control Systems; SP-025 Advanced Monitoring and Detection; SP-029 Zero Trust Architecture; SP-037 Privileged User Management

## Clauses by framework (63 frameworks)
- iso_27001_2022: A.8.2, A.8.4, A.8.9, A.8.19, A.8.31, A.8.32
- iso_27002_2022: 5.37, 8.4, 8.9, 8.19, 8.32
- cobit_2019: BAI06, BAI10
- pci_dss_v4: 6.5
- nist_csf_2: PR.PS-01
- cis_controls_v8: CIS 4.6, CIS 12.3
- finos_ccc: CCC-C07
- iso_42001_2023: A.6.2.5
- bsi_grundschutz: OPS.1.1.2
- anssi: Hygiene.15, Hygiene.16, Hygiene.17, Hygiene.34, SecNumCloud.13.2
- osfi_b13: B-13.2.3, B-13.3.2
- finma_circular: IV.A(36), IV.A(37), IV.B.d(59)
- gdpr: Art.32(1)(b)
- dora: Art.9(4)(c), Art.9(4)(e)
- bio2: 5.37, 8.4, 8.9, 8.19, 8.32
- rbi_csf: Annex1.7, ITGRCA.13
- fisc: FISC.O3
- hkma_tme1: TME1.3.3, TME1.4.1, TME1.4.2
- mlps_2: 8.1.5.1, 8.1.10.8
- dnb_good_practice: DNB.7.1, DNB.10.1, DNB.10.5
- swift_cscf: SWIFT.6.2
- cbb_tm: TM-5
- cbuae: CR-7
- nca_ecc: 2-3
- qatar_nia: OS, SD
- sama_csf: 3.5
- uae_ia: T7, T10
- bog_cisd: CISD-VI
- bom_ctrm: 3.6
- cbe_csf: CTO-12
- cbn_csf: Part3.3
- sa_js2: JS2-7.2
- bot_cyber: Ch2.1
- cpmi_pfmi: CG.PR
- eba_ict: 3.4.4, 3.6.3
- ecb_croe: CROE.2.3.4
- ffiec_is: II.C.7(c), II.C.10
- iosco_cyber: PROT-6
- sebi_cscrf: PR.IP
- cmmc_2: CM
- nrc_73_54: RG5.71-B-CM
- ieee_1686: 5.4
- doe_c2m2: ASSET
- pci_pts: B
- fips_140: FIPS 140-3 §7.11
- pci_hsm: 4
- common_criteria: CC Part 2 — FMT
- isae_3402: Clause 4
- fca_sysc_13: SYSC 13.6.2, SYSC 13.7.4
- fda_21_cfr_11: §11.10(k)
- fda_cyber: SA-3
- hitrust_csf: 09.a
- lloyds_ms: MS5.1, MS8.4
- naic_ds: 4-config
- nhs_dspt: NDG-4.4
- pra_ss1_23: P3.3, P3.4
- solvency_ii: EIOPA-ICT-4.8, EIOPA-ICT-4.11
- csa_ccm_v4: CCC-03, CCC-04
- csa_aicm: CCC-03, CCC-04, IAM-19, MDS-04, MDS-07
- ccss_v9: 1.01.3
- basel_sco60: SCO60.52, SCO60.66
- bssc: GSP-14, TIS-08
- sec_custody_digital: SEC-CD-05
OSA's mapping for iso_27001_2022 and nist_csf_2 takes NIST's published crosswalk as its base. A clause not marked as OSA's own is in that crosswalk.

## More
- This control as JSON, with guidance and ATT&CK techniques: /api/v1/controls/CM-05
- Clauses only: /api/v1/controls/CM-05?fields=mappings
- Page for people: /controls/cm-05/
