Configuration Change Control (CM-3)
Determine and document the types of changes to the system that are configuration-controlled; Review proposed configuration-controlled changes to the system and approve or disapprove such changes with explicit consideration for security and privacy impact analyses; Document configuration change decisions associated with the system; Implement approved configuration-controlled changes to the system; Retain records of configuration-controlled changes to the system for [organization-defined]; Monitor
Security Baselines
Why These Connect
These are equivalent or closely aligned requirements in other frameworks.
This control is included in the linked security baseline (LOW, MODERATE, or HIGH).
These related controls work together — a change to one may affect the others.
These enhancements add specific capabilities or refinements to the base control.