|
controlCM-4
Impact Analyses (CM-4)
Analyze changes to the system to determine potential security and privacy impacts prior to change implementation.
Security Baselines
LOWMODERATEHIGH
configurationbaselineschange-control
Why These Connect
Maps To5
These are equivalent or closely aligned requirements in other frameworks.
Baselined In3
This control is included in the linked security baseline (LOW, MODERATE, or HIGH).
Supports26
These related controls work together — a change to one may affect the others.
Enhances2
These enhancements add specific capabilities or refinements to the base control.
Related Controls(18)
CA-7Continuous Monitoring (CA-7)
LMH
CM-3Configuration Change Control (CM-3)MH
CM-8System Component Inventory (CM-8)LMH
CM-9Configuration Management Plan (CM-9)MH
MA-2Controlled Maintenance (MA-2)LMH
RA-3Risk Assessment (RA-3)LMH
RA-5Vulnerability Monitoring and Scanning (RA-5)LMH
RA-8Privacy Impact Assessments (RA-8)SA-5System Documentation (SA-5)LMH
SA-8Security and Privacy Engineering Principles (SA-8)LMH
SA-10Developer Configuration Management (SA-10)MH
SI-2Flaw Remediation (SI-2)LMH
CM-13Data Action Mapping (CM-13)PM-31Continuous Monitoring Strategy (PM-31)SA-11Developer Testing and Evaluation (SA-11)MH
SC-3Security Function Isolation (SC-3)H
SC-7Boundary Protection (SC-7)LMH
SI-6Security and Privacy Function Verification (SI-6)H
Cross-Framework Mappings(5)
ID.RA-07ID.RA-07Final
NIST OLIR informative reference — Cybersecurity Framework v2.0 to SP 800-53 Rev 5
PR.PS-01PR.PS-01Final
NIST OLIR informative reference — Cybersecurity Framework v2.0 to SP 800-53 Rev 5
ISO 27001ISO/IEC 27001:20221 mappingFinal
NIST OLIR informative reference — SP 800-53 Rev 5 to ISO/IEC 27001:2022
ID.RA-07ID.RA-07Final
NIST OLIR informative reference — Cybersecurity Framework v2.0 to SP 800-53 Rev 5
PR.PS-01PR.PS-01Final
NIST OLIR informative reference — Cybersecurity Framework v2.0 to SP 800-53 Rev 5