EvidenceSheet

CM-5(5) Access Restrictions for Change | Privilege Limitation for Production and Operation. (a) Limit privileges to change system components and system-related information within a production or operational environment; and (b) Review and reevaluate privileges [Assignment:

Access Restrictions for Change | Privilege Limitation for Production and Operation. (a) Limit privileges to change system components and system-related information within a production or operational environment; and (b) .

5
artefacts
2
held by a system
2
at each review
moderate
to go live
Identity provider / directory
where the evidence lives
teal = a system already holds it · olive = produced at each review

system holds itEvidence a system already holds

  • Identification of the accounts and roles holding those privileges, extracted from the production environment itself · Identity provider / directory
  • Configuration evidence that developers and other non-operational roles cannot change production components · Identity provider / directory

periodic reviewEvidence produced at each review

  • User privilege review records at the defined frequency, showing privileges reviewed and reevaluated · Cloud console / configuration management
  • Records of privileges removed or reduced as a result of a review · Cloud console / configuration management

governing documentDocuments that govern the control

  • Documented list of privileges that permit change to system components and system related information in the production or operational environment · Policy repository / GRC workspace

First move

Start with the 2 of 5 artefacts that already live in a system (Identity provider / directory); keep the periodic reviews but log each one as a dated record with a named reviewer.

Common gaps auditors find

Do this for your whole sheet

Paste the rows you run your controls from and get this mapping for every control at once, with the periodic-review ones flagged and a first move per row. No account for the first run.

Build my evidence sheet

CM-5(1) Access Restrictions for Change | Automated Access Enforcement and Audit Records. (a) Enforce access restrictions using [Assignment: organization-defined automated mechanisms]; and (b) Automatically generate audit records of the enforcement actions · CM-6 Configuration Settings