Asset & Configuration Management

Change Control. Engineered.

CM.L2-3.4.3 requires you to track, review, approve, and log every change to systems in scope — and CM.L2-3.4.4 requires analyzing the security impact before the change is made. The Change Control module runs that workflow end to end: a change request, a documented impact analysis, an approval decision, and a permanent log entry linked to the assets and baselines the change affects.

CM.L2 3.4.3, 3.4.4 and 3.4.5
Impact first Analyzed before implementation
Logged Permanent approval record
Capability

A Change Workflow With a Paper Trail

Every change to a system in scope — a firewall rule, a new application, a server rebuild, an access modification — is entered as a change request describing what is changing, why, and which systems are affected. The request moves through defined states: submitted, reviewed, approved or rejected, implemented, and closed. Nothing is approved without a record of who approved it and when, and nothing is closed without confirmation that the change was completed as described.

That workflow is the difference between making changes and managing them. When an assessor examines CM.L2-3.4.3, they are looking for evidence that changes are controlled rather than ad hoc — a documented request, a review, an approval, and a log. The module produces that evidence as a byproduct of the work, not as a separate documentation exercise.

Dashboard Requirements Evidence POA&M Reports
1TEN Change Control interface showing change requests with security impact analysis and approval status
Capability

Security Impact Analysis Before Implementation

CM.L2-3.4.4 requires analyzing the security impact of a change before it is implemented — not after something breaks. Each change request carries a security impact analysis field where the requester and reviewer document which controls the change could affect, whether it expands or contracts the assessment boundary, and what is needed to keep the affected requirements satisfied. A change that touches the CUI enclave gets a different level of scrutiny than swapping a monitor, and the record shows that judgment was exercised.

Changes that alter physical or logical access are governed under CM.L2-3.4.5: the approval step enforces who is permitted to authorize that class of change, so access-affecting changes cannot route around the people responsible for them. The result is a change record an assessor can follow from request to approval to implementation without gaps.

Inside the Module

What You See Inside

Change request records
What is changing, why, and the affected systems, captured in a structured request.
Security impact analysis
Documented assessment of affected controls and scope impact before the change proceeds.
Approval workflow
Defined states with named approvers; access-affecting changes enforce who may authorize them.
Baseline linkage
Approved changes link to the configuration baseline version they affect.
Asset linkage
Each change connects to the assets in the inventory it modifies.
Immutable change log
A permanent, timestamped record of every change, approval, and closure for assessment.
The problem this solves

Small teams change things constantly and rarely write any of it down. The firewall gets a new rule, a server gets rebuilt, an account gets elevated — and six months later nobody can say who approved it or what it affected. CM.L2-3.4.3 and 3.4.4 exist precisely because uncontrolled change is how a compliant environment quietly drifts out of compliance. A lightweight request-review-approve-log workflow keeps the trail intact without turning every change into a committee, so the environment evolves on the record instead of off it.

Practices

Practices Satisfied

Practice IDDescription
CM.L2-3.4.3 Track, review, approve or disapprove, and log changes to organizational systems.
CM.L2-3.4.4 Analyze the security impact of changes prior to implementation.
CM.L2-3.4.5 Define, document, approve, and enforce physical and logical access restrictions associated with changes to organizational systems.
Connected Modules

Related Modules

All 14 domains.

1TEN tracks control implementation, manages your POA&M, and organizes evidence across every NIST SP 800-171 requirement.

Request a Demo