NIST 800-171 v2

110 security requirements available

3.4.5Derived Requirement

Configuration Management

Security Requirement

Define, document, approve, and enforce physical and logical access restrictions associated with changes to organizational systems.

Discussion

Any changes to the hardware, software, or firmware components of systems can potentially have significant effects on the overall security of the systems. Therefore, organizations permit only qualified and authorized individuals to access systems for purposes of initiating changes, including upgrades and modifications. Access restrictions for change also include software libraries. Access restrictions include physical and logical access control requirements, workflow automation, media libraries, abstract layers (e.g., changes implemented into external interfaces rather than directly into systems), and change windows (e.g., changes occur only during certain specified times). In addition to security concerns, commonly-accepted due diligence for configuration management includes access restrictions as an essential part in ensuring the ability to effectively manage the configuration. [SP 800-128] provides guidance on configuration change control.

Framework
NIST SP 800-171 Rev 2
Family
Configuration Management
Requirement Type
derived

Related Frameworks

11 paths across 2 frameworks
NIST 800-531 mapping
CM-5
1.00
  • NIST · Rev 2 (Feb 2020, errata Jan 2021) · nist_800_171_app_d · equivalent
CCI10 mappings
CCI-000338
1.00
  • NIST · Rev 2 (Feb 2020, errata Jan 2021) · nist_800_171_app_d · equivalent
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-000339
1.00
  • NIST · Rev 2 (Feb 2020, errata Jan 2021) · nist_800_171_app_d · equivalent
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-000340
1.00
  • NIST · Rev 2 (Feb 2020, errata Jan 2021) · nist_800_171_app_d · equivalent
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-000341
1.00
  • NIST · Rev 2 (Feb 2020, errata Jan 2021) · nist_800_171_app_d · equivalent
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-000342
1.00
  • NIST · Rev 2 (Feb 2020, errata Jan 2021) · nist_800_171_app_d · equivalent
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-000343
1.00
  • NIST · Rev 2 (Feb 2020, errata Jan 2021) · nist_800_171_app_d · equivalent
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-000344
1.00
  • NIST · Rev 2 (Feb 2020, errata Jan 2021) · nist_800_171_app_d · equivalent
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-000345
1.00
  • NIST · Rev 2 (Feb 2020, errata Jan 2021) · nist_800_171_app_d · equivalent
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-003935
1.00
  • NIST · Rev 2 (Feb 2020, errata Jan 2021) · nist_800_171_app_d · equivalent
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-003936
1.00
  • NIST · Rev 2 (Feb 2020, errata Jan 2021) · nist_800_171_app_d · equivalent
  • DISA · 2025-01-23 · disa_cci_list · equivalent

Related STIGs

338 STIGs reach this control through 35 CCIs via 800-53 control CM-5. Expand a row to see the responsible NICE and O*NET roles.

Operating System — Desktop

4 STIGs

Operating System — Server

31 STIGs
Show 23 more STIGs in this category →
Oracle Linux 9 Security Technical Implementation Guide
V1R52026-02-1711 of 448 findings match
Amazon Linux 2023 Security Technical Implementation Guide
V1R32026-02-2710 of 187 findings match
IBM AIX 7.x Security Technical Implementation Guide
V3R22026-02-069 of 283 findings match
IBM AIX 7.x Security Technical Implementation Guide
32024-08-169 of 283 findings match
Oracle Linux 8 Security Technical Implementation Guide
V2R82026-02-139 of 375 findings match

Operating System — Mainframe

158 STIGs
CA IDMS Security Technical Implementation Guide
V2R12024-09-138 of 74 findings match
Mainframe Product Security Requirements Guide
V3R42025-09-105 of 194 findings match
Mainframe Product Security Requirements Guide
32024-12-055 of 193 findings match
Show 150 more STIGs in this category →
IBM z/OS ACF2 Security Technical Implementation Guide
V9R82026-03-093 of 225 findings match
IBM z/OS RACF Security Technical Implementation Guide
V9R82026-03-093 of 222 findings match
IBM z/OS TSS Security Technical Implementation Guide
V9R82026-03-093 of 230 findings match

Network Device

37 STIGs
Network Device Management Security Requirements Guide
V5R32025-02-114 of 104 findings match
Network Device Management Security Requirements Guide
V5R42025-09-104 of 105 findings match
Show 29 more STIGs in this category →
SDN Controller Security Requirements Guide
22024-05-282 of 34 findings match
AAA Services Security Requirements Guide
V2R22024-12-041 of 77 findings match
Cisco ACI NDM Security Technical Implementation Guide
V1R22025-12-111 of 26 findings match
Cisco ISE NDM Security Technical Implementation Guide
V2R32025-12-111 of 53 findings match
Domain Name System (DNS) Security Requirements Guide
V4R22025-12-191 of 119 findings match
F5 NGINX Security Technical Implementation Guide
V1R12026-01-071 of 32 findings match

Database

29 STIGs
Database Security Requirements Guide
V4R52026-02-267 of 142 findings match
Database Security Requirements Guide
42024-12-047 of 142 findings match
Show 21 more STIGs in this category →

Web / Application Server

21 STIGs
Application Server Security Requirements Guide
V4R42025-09-103 of 137 findings match
Application Server Security Requirements Guide
42025-02-113 of 128 findings match
Show 13 more STIGs in this category →
Web Server Security Requirements Guide
V4R42025-09-102 of 126 findings match
Web Server Security Requirements Guide
42025-02-122 of 124 findings match

Virtualization / Container

32 STIGs
Container Platform Security Requirements Guide
V2R42025-09-108 of 188 findings match
Container Platform Security Requirements Guide
22025-05-158 of 187 findings match
Kubernetes Security Technical Implementation Guide
V2R62026-02-125 of 92 findings match
Virtual Machine Manager Security Requirements Guide
22024-12-063 of 193 findings match
Virtual Machine Manager Security Requirements Guide
V2R32025-09-103 of 198 findings match
Show 24 more STIGs in this category →

Endpoint Security Management

16 STIGs
Tanium 7.x Security Technical Implementation Guide
V2R32025-05-144 of 98 findings match
ISEC7 Sphere Security Technical Implementation Guide
V3R12024-08-202 of 34 findings match
Central Log Server Security Requirements Guide
V3R42026-02-121 of 127 findings match
Show 8 more STIGs in this category →
Central Log Server Security Requirements Guide
32024-12-041 of 125 findings match
HYCU Protege Security Technical Implementation Guide
V1R22026-03-041 of 55 findings match

Productivity Application

2 STIGs

Uncategorized

8 STIGs