NIST SP 800-53 Rev. 5 · Configuration Management

CM-6 / CM-3 — Configuration Settings / Configuration Change Control

Configuration deviation without an approved change. Published queries for three platforms, each with the evidence it needs and the limits of what it shows.

Why this matters

A security setting quietly changed with no approval behind it

Organizations agree a standard configuration and a process for changing it. Under time pressure the setting gets changed directly and the paperwork never follows, and the change is indistinguishable from one that was properly approved. Many changes are entirely legitimate, so reporting every change produces a list nobody reads.

Why this check earns its place. It reports only changes with no approval record behind them, which is a far shorter and far more useful list than every change that occurred.

What it reads
The organization's current settings, compared against its agreed standard and its own record of approved changes.
What it reports
Settings that differ from the agreed standard with no matching approval on record.

See related public disclosures on the Signals page →

The requirement

The organization must establish and document configuration settings that reflect the most restrictive mode consistent with operational requirements, identify and document any deviations, and approve and control changes under configuration change control.

NIST SP 800-53 Rev. 5 — CM-6 (Configuration Settings) and CM-3 (Configuration Change Control).

NIST requires documented settings and controlled change. The approved baseline values, in-scope resources, the tolerance window for matching a change to an approval, and pre-authorized automation identities are all organization-defined.

What a check finds

Security-relevant configuration differs from the approved baseline with no matching approved change record.

Choose your platform

CISA performance goals

  • 3.N — Establish change management processes
  • 3.P — Maintain hardware & software approval process (partial)

Full coverage map →

What a result does not prove

An unmatched deviation is not automatically unauthorized or harmful. Approval evidence usually lives outside the cloud platform, and correlation depends entirely on the completeness of the change feed.