CM-5 Access Restrictions for Change
Configuration Management family. 35 Control Correlation Identifiers map to this control, and 41 STIG rules implement those CCIs.
The mapping below is derived from 8 DISA STIG benchmarks (Google Chrome Current Windows, Kubernetes, Microsoft Windows 10, Microsoft Windows 11, Microsoft Windows Server 2019, Microsoft Windows Server 2022, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9) covering 2,030 rules, joined to 5,137 Control Correlation Identifiers.
It is not the complete STIG library. A control showing no rules here means no rule in these benchmarks maps to it, not that no STIG covers it. CCI to control mappings are published by DISA and reflect both Revision 4 and Revision 5 of NIST SP 800-53; where the two revisions disagree, both are shown. This page reports what the source data says and nothing further. It is not a compliance determination.
Where these rules come from
| STIG benchmark | Version | Rules mapped to CM-5 |
|---|---|---|
| Red Hat Enterprise Linux 9 | V2 | 19 |
| Red Hat Enterprise Linux 8 | V2 | 13 |
| Kubernetes | V2 | 5 |
| Microsoft Windows 10 | V3 | 2 |
| Microsoft Windows 11 | V2 | 2 |
Control Correlation Identifiers mapped to CM-5
| CCI | Definition | Rev |
|---|---|---|
| CCI-000338 | The organization defines physical access restrictions associated with changes to the information system. | 4 |
| CCI-000339 | The organization documents physical access restrictions associated with changes to the information system. | 4 |
| CCI-000340 | Approve physical access restrictions associated with changes to the system. | 5, 4 |
| CCI-000341 | Enforce physical access restrictions associated with changes to the system. | 5, 4 |
| CCI-000342 | The organization defines logical access restrictions associated with changes to the information system. | 4 |
| CCI-000343 | The organization documents logical access restrictions associated with changes to the information system. | 4 |
| CCI-000344 | Approve logical access restrictions associated with changes to the system. | 5, 4 |
| CCI-000345 | Enforce logical access restrictions associated with changes to the system. | 5, 4 |
| CCI-000348 | The organization defines a frequency with which to conduct reviews of information system changes. | 4 |
| CCI-000349 | The organization reviews information system changes per organization-defined frequency to determine whether unauthorized changes have occurred. | 4 |
| CCI-000350 | The organization reviews information system changes upon organization-defined circumstances to determine whether unauthorized changes have occurred. | 4 |
| CCI-000353 | Defines system components requiring enforcement of a dual authorization for system changes. | 5, 4 |
| CCI-000354 | Enforce dual authorization for implementing changes to organization-defined system components. | 5, 4 |
| CCI-001499 | Limit privileges to change software resident within software libraries. | 5, 4 |
| CCI-001747 | The organization defines critical software components the information system will prevent from being installed without verification the component has been digitally signed using a certificate that is recognized and approved by the organization. | 4 |
| CCI-001748 | The organization defines critical firmware components the information system will prevent from being installed without verification the component has been digitally signed using a certificate that is recognized and approved by the organization. | 4 |
| CCI-001749 | The information system prevents the installation of organization-defined software components without verification the software component has been digitally signed using a certificate that is recognized and approved by the organization. | 4 |
| CCI-001750 | The information system prevents the installation of organization-defined firmware components without verification the firmware component has been digitally signed using a certificate that is recognized and approved by the organization. | 4 |
| CCI-001751 | Defines system-level information requiring enforcement of a dual authorization for system changes. | 5, 4 |
| CCI-001752 | Enforce dual authorization for implementing changes to organization-defined system-level information. | 5, 4 |
| CCI-001753 | Limit privileges to change system components within a production or operational environment. | 5, 4 |
| CCI-001754 | Limit privileges to change system-related information within a production or operational environment. | 5, 4 |
| CCI-001813 | Enforce access restrictions using organization-defined mechanisms. | 5, 4 |
| CCI-001814 | The Information system supports auditing of the enforcement actions. | 4 |
| CCI-001826 | The organization defines the circumstances upon which the organization reviews the information system changes to determine whether unauthorized changes have occurred. | 4 |
| CCI-001827 | The organization defines the frequency with which to review information system privileges. | 4 |
| CCI-001828 | The organization defines the frequency with which to reevaluate information system privileges. | 4 |
| CCI-001829 | The organization reviews information system privileges per an organization-defined frequency. | 4 |
| CCI-001830 | The organization reevaluates information system privileges per an organization-defined frequency. | 4 |
| CCI-003935 | Define and document physical access restrictions associated with changes to the system. | 5 |
| CCI-003936 | Define and document logical access restrictions associated with changes to the system. | 5 |
| CCI-003937 | Defines the automated mechanisms to enforce access restrictions. | 5 |
| CCI-003938 | Automatically generate audit records of the enforcement actions. | 5 |
| CCI-003939 | Defines the frequency with which to review and reevaluate system privileges. | 5 |
| CCI-003940 | Review and reevaluate system privileges per an organization-defined frequency. | 5 |
STIG rules that implement CM-5
| Rule | STIG ID | Severity | Requirement |
|---|---|---|---|
| V-220753 | WN10-AU-000045 | medium | The system must be configured to audit Detailed Tracking - PNP Activity successes. |
| V-220754 | WN10-AU-000050 | medium | The system must be configured to audit Detailed Tracking - Process Creation successes. |
| V-230257 | RHEL-08-010300 | medium | RHEL 8 system commands must have mode 755 or less permissive. |
| V-230258 | RHEL-08-010310 | medium | RHEL 8 system commands must be owned by root. |
| V-230259 | RHEL-08-010320 | medium | RHEL 8 system commands must be group-owned by root or a system account. |
| V-230260 | RHEL-08-010330 | medium | RHEL 8 library files must have mode 755 or less permissive. |
| V-230261 | RHEL-08-010340 | medium | RHEL 8 library files must be owned by root. |
| V-230262 | RHEL-08-010350 | medium | RHEL 8 library files must be group-owned by root or a system account. |
| V-230264 | RHEL-08-010370 | high | RHEL 8 must prevent the installation of software, patches, service packs, device drivers, or operating system components from a repository without verification they have been digitally signed using a certificate that is issued by a Certificate Authority (CA) that is recognized and approved by the organization. |
| V-230265 | RHEL-08-010371 | high | RHEL 8 must prevent the installation of software, patches, service packs, device drivers, or operating system components of local packages without verification they have been digitally signed using a certificate that is issued by a Certificate Authority (CA) that is recognized and approved by the organization. |
| V-230266 | RHEL-08-010372 | medium | RHEL 8 must prevent the loading of a new kernel for later execution. |
| V-242404 | CNTR-K8-000850 | medium | Kubernetes Kubelet must deny hostname override. |
| V-242405 | CNTR-K8-000860 | medium | The Kubernetes manifests must be owned by root. |
| V-242406 | CNTR-K8-000880 | medium | The Kubernetes KubeletConfiguration file must be owned by root. |
| V-242407 | CNTR-K8-000890 | medium | The Kubernetes KubeletConfiguration files must have file permissions set to 644 or more restrictive. |
| V-242408 | CNTR-K8-000900 | medium | The Kubernetes manifest files must have least privileges. |
| V-251707 | RHEL-08-010331 | medium | RHEL 8 library directories must have mode 755 or less permissive. |
| V-251708 | RHEL-08-010341 | medium | RHEL 8 library directories must be owned by root. |
| V-251709 | RHEL-08-010351 | medium | RHEL 8 library directories must be group-owned by root or a system account. |
| V-253311 | WN11-AU-000045 | medium | The system must be configured to audit Detailed Tracking - PNP Activity successes. |
| V-253312 | WN11-AU-000050 | medium | The system must be configured to audit Detailed Tracking - Process Creation successes. |
| V-256973 | RHEL-08-010019 | medium | RHEL 8 must ensure cryptographic verification of vendor software packages. |
| V-257799 | RHEL-09-213020 | medium | RHEL 9 must prevent the loading of a new kernel for later execution. |
| V-257819 | RHEL-09-214010 | medium | RHEL 9 must ensure cryptographic verification of vendor software packages. |
| V-257820 | RHEL-09-214015 | high | RHEL 9 must check the GPG signature of software packages originating from external software repositories before installation. |
| V-257821 | RHEL-09-214020 | high | RHEL 9 must check the GPG signature of locally installed software packages before installation. |
| V-257822 | RHEL-09-214025 | high | RHEL 9 must have GPG signature verification enabled for all software repositories. |
| V-257825 | RHEL-09-215010 | medium | RHEL 9 subscription-manager package must be installed. |
| V-257882 | RHEL-09-232010 | medium | RHEL 9 system commands must have mode 755 or less permissive. |
| V-257883 | RHEL-09-232015 | medium | RHEL 9 library directories must have mode 755 or less permissive. |
| V-257884 | RHEL-09-232020 | medium | RHEL 9 library files must have mode 755 or less permissive. |
| V-257918 | RHEL-09-232190 | medium | RHEL 9 system commands must be owned by root. |
| V-257919 | RHEL-09-232195 | medium | RHEL 9 system commands must be group-owned by root or a system account. |
| V-257920 | RHEL-09-232200 | medium | RHEL 9 library files must be owned by root. |
| V-257921 | RHEL-09-232205 | medium | RHEL 9 library files must be group-owned by root or a system account. |
| V-257922 | RHEL-09-232210 | medium | RHEL 9 library directories must be owned by root. |
| V-257923 | RHEL-09-232215 | medium | RHEL 9 library directories must be group-owned by root or a system account. |
| V-258003 | RHEL-09-255135 | medium | RHEL 9 SSH daemon must not allow GSSAPI authentication. |
| V-258004 | RHEL-09-255140 | medium | RHEL 9 SSH daemon must not allow Kerberos authentication. |
| V-258151 | RHEL-09-653010 | medium | RHEL 9 audit package must be installed. |
| V-258152 | RHEL-09-653015 | medium | RHEL 9 audit service must be enabled. |
Get this as data
The same mapping is served as JSON, no key required: /api/v1/stig-nist/control/CM-5. The interactive version of the full cube is the STIG to NIST mapper, and the endpoint is documented on the compliance API page.