San Antonio, TX · Military City, USA UEI L58JZMKRCLM5  ·  CAGE 203C1  ·  NAICS 541511  ·  SAM.gov Active

CM-5 Access Restrictions for Change

Configuration Management family. 35 Control Correlation Identifiers map to this control, and 41 STIG rules implement those CCIs.

5CAT I (high)
36CAT II (medium)
0CAT III (low)
35CCIs
What this page is built from, and what it is not.

The mapping below is derived from 8 DISA STIG benchmarks (Google Chrome Current Windows, Kubernetes, Microsoft Windows 10, Microsoft Windows 11, Microsoft Windows Server 2019, Microsoft Windows Server 2022, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9) covering 2,030 rules, joined to 5,137 Control Correlation Identifiers.

It is not the complete STIG library. A control showing no rules here means no rule in these benchmarks maps to it, not that no STIG covers it. CCI to control mappings are published by DISA and reflect both Revision 4 and Revision 5 of NIST SP 800-53; where the two revisions disagree, both are shown. This page reports what the source data says and nothing further. It is not a compliance determination.

Where these rules come from

STIG benchmarkVersionRules mapped to CM-5
Red Hat Enterprise Linux 9V219
Red Hat Enterprise Linux 8V213
KubernetesV25
Microsoft Windows 10V32
Microsoft Windows 11V22

Control Correlation Identifiers mapped to CM-5

CCIDefinitionRev
CCI-000338The organization defines physical access restrictions associated with changes to the information system.4
CCI-000339The organization documents physical access restrictions associated with changes to the information system.4
CCI-000340Approve physical access restrictions associated with changes to the system.5, 4
CCI-000341Enforce physical access restrictions associated with changes to the system.5, 4
CCI-000342The organization defines logical access restrictions associated with changes to the information system.4
CCI-000343The organization documents logical access restrictions associated with changes to the information system.4
CCI-000344Approve logical access restrictions associated with changes to the system.5, 4
CCI-000345Enforce logical access restrictions associated with changes to the system.5, 4
CCI-000348The organization defines a frequency with which to conduct reviews of information system changes.4
CCI-000349The organization reviews information system changes per organization-defined frequency to determine whether unauthorized changes have occurred.4
CCI-000350The organization reviews information system changes upon organization-defined circumstances to determine whether unauthorized changes have occurred.4
CCI-000353Defines system components requiring enforcement of a dual authorization for system changes.5, 4
CCI-000354Enforce dual authorization for implementing changes to organization-defined system components.5, 4
CCI-001499Limit privileges to change software resident within software libraries.5, 4
CCI-001747The organization defines critical software components the information system will prevent from being installed without verification the component has been digitally signed using a certificate that is recognized and approved by the organization.4
CCI-001748The organization defines critical firmware components the information system will prevent from being installed without verification the component has been digitally signed using a certificate that is recognized and approved by the organization.4
CCI-001749The information system prevents the installation of organization-defined software components without verification the software component has been digitally signed using a certificate that is recognized and approved by the organization.4
CCI-001750The information system prevents the installation of organization-defined firmware components without verification the firmware component has been digitally signed using a certificate that is recognized and approved by the organization.4
CCI-001751Defines system-level information requiring enforcement of a dual authorization for system changes.5, 4
CCI-001752Enforce dual authorization for implementing changes to organization-defined system-level information.5, 4
CCI-001753Limit privileges to change system components within a production or operational environment.5, 4
CCI-001754Limit privileges to change system-related information within a production or operational environment.5, 4
CCI-001813Enforce access restrictions using organization-defined mechanisms.5, 4
CCI-001814The Information system supports auditing of the enforcement actions.4
CCI-001826The organization defines the circumstances upon which the organization reviews the information system changes to determine whether unauthorized changes have occurred.4
CCI-001827The organization defines the frequency with which to review information system privileges.4
CCI-001828The organization defines the frequency with which to reevaluate information system privileges.4
CCI-001829The organization reviews information system privileges per an organization-defined frequency.4
CCI-001830The organization reevaluates information system privileges per an organization-defined frequency.4
CCI-003935Define and document physical access restrictions associated with changes to the system.5
CCI-003936Define and document logical access restrictions associated with changes to the system.5
CCI-003937Defines the automated mechanisms to enforce access restrictions.5
CCI-003938Automatically generate audit records of the enforcement actions.5
CCI-003939Defines the frequency with which to review and reevaluate system privileges.5
CCI-003940Review and reevaluate system privileges per an organization-defined frequency.5

STIG rules that implement CM-5

RuleSTIG IDSeverityRequirement
V-220753WN10-AU-000045mediumThe system must be configured to audit Detailed Tracking - PNP Activity successes.
V-220754WN10-AU-000050mediumThe system must be configured to audit Detailed Tracking - Process Creation successes.
V-230257RHEL-08-010300mediumRHEL 8 system commands must have mode 755 or less permissive.
V-230258RHEL-08-010310mediumRHEL 8 system commands must be owned by root.
V-230259RHEL-08-010320mediumRHEL 8 system commands must be group-owned by root or a system account.
V-230260RHEL-08-010330mediumRHEL 8 library files must have mode 755 or less permissive.
V-230261RHEL-08-010340mediumRHEL 8 library files must be owned by root.
V-230262RHEL-08-010350mediumRHEL 8 library files must be group-owned by root or a system account.
V-230264RHEL-08-010370highRHEL 8 must prevent the installation of software, patches, service packs, device drivers, or operating system components from a repository without verification they have been digitally signed using a certificate that is issued by a Certificate Authority (CA) that is recognized and approved by the organization.
V-230265RHEL-08-010371highRHEL 8 must prevent the installation of software, patches, service packs, device drivers, or operating system components of local packages without verification they have been digitally signed using a certificate that is issued by a Certificate Authority (CA) that is recognized and approved by the organization.
V-230266RHEL-08-010372mediumRHEL 8 must prevent the loading of a new kernel for later execution.
V-242404CNTR-K8-000850mediumKubernetes Kubelet must deny hostname override.
V-242405CNTR-K8-000860mediumThe Kubernetes manifests must be owned by root.
V-242406CNTR-K8-000880mediumThe Kubernetes KubeletConfiguration file must be owned by root.
V-242407CNTR-K8-000890mediumThe Kubernetes KubeletConfiguration files must have file permissions set to 644 or more restrictive.
V-242408CNTR-K8-000900mediumThe Kubernetes manifest files must have least privileges.
V-251707RHEL-08-010331mediumRHEL 8 library directories must have mode 755 or less permissive.
V-251708RHEL-08-010341mediumRHEL 8 library directories must be owned by root.
V-251709RHEL-08-010351mediumRHEL 8 library directories must be group-owned by root or a system account.
V-253311WN11-AU-000045mediumThe system must be configured to audit Detailed Tracking - PNP Activity successes.
V-253312WN11-AU-000050mediumThe system must be configured to audit Detailed Tracking - Process Creation successes.
V-256973RHEL-08-010019mediumRHEL 8 must ensure cryptographic verification of vendor software packages.
V-257799RHEL-09-213020mediumRHEL 9 must prevent the loading of a new kernel for later execution.
V-257819RHEL-09-214010mediumRHEL 9 must ensure cryptographic verification of vendor software packages.
V-257820RHEL-09-214015highRHEL 9 must check the GPG signature of software packages originating from external software repositories before installation.
V-257821RHEL-09-214020highRHEL 9 must check the GPG signature of locally installed software packages before installation.
V-257822RHEL-09-214025highRHEL 9 must have GPG signature verification enabled for all software repositories.
V-257825RHEL-09-215010mediumRHEL 9 subscription-manager package must be installed.
V-257882RHEL-09-232010mediumRHEL 9 system commands must have mode 755 or less permissive.
V-257883RHEL-09-232015mediumRHEL 9 library directories must have mode 755 or less permissive.
V-257884RHEL-09-232020mediumRHEL 9 library files must have mode 755 or less permissive.
V-257918RHEL-09-232190mediumRHEL 9 system commands must be owned by root.
V-257919RHEL-09-232195mediumRHEL 9 system commands must be group-owned by root or a system account.
V-257920RHEL-09-232200mediumRHEL 9 library files must be owned by root.
V-257921RHEL-09-232205mediumRHEL 9 library files must be group-owned by root or a system account.
V-257922RHEL-09-232210mediumRHEL 9 library directories must be owned by root.
V-257923RHEL-09-232215mediumRHEL 9 library directories must be group-owned by root or a system account.
V-258003RHEL-09-255135mediumRHEL 9 SSH daemon must not allow GSSAPI authentication.
V-258004RHEL-09-255140mediumRHEL 9 SSH daemon must not allow Kerberos authentication.
V-258151RHEL-09-653010mediumRHEL 9 audit package must be installed.
V-258152RHEL-09-653015mediumRHEL 9 audit service must be enabled.

Get this as data

The same mapping is served as JSON, no key required: /api/v1/stig-nist/control/CM-5. The interactive version of the full cube is the STIG to NIST mapper, and the endpoint is documented on the compliance API page.