HomeControl Library › 3.4.5
3.4 Configuration Management5 pts

3.4.5 — Restrict who can make changes

Define, document, approve, and enforce physical and logical access restrictions associated with changes to organizational systems.

Only authorized people can change systems — enforced physically and logically.

What it actually means

The ability to change systems is itself a privilege that must be restricted and enforced — both logically (who has the rights to push a change) and physically (who can get to the equipment). It ties change control to least privilege.

Pass or fail — an assessor needs a "yes" to each

What to have ready

Where teams trip up

See where this control puts your score

Run all 110 requirements free in about 10 minutes.

Calculate your SPRS score →

Connected requirements

← Back to the Control Library