CM-5(5) Access Restrictions for Change | Privilege Limitation for Production and Operation. (a) Limit privileges to change system components and system-related information within a production or operational environment; and (b) Review and reevaluate privileges [Assignment:
Access Restrictions for Change | Privilege Limitation for Production and Operation. (a) Limit privileges to change system components and system-related information within a production or operational environment; and (b) .
5
artefacts
2
held by a system
2
at each review
moderate
to go live
Identity provider / directory
where the evidence lives
teal = a system already holds it · olive = produced at each review
system holds itEvidence a system already holds
- Identification of the accounts and roles holding those privileges, extracted from the production environment itself · Identity provider / directory
- Configuration evidence that developers and other non-operational roles cannot change production components · Identity provider / directory
periodic reviewEvidence produced at each review
- User privilege review records at the defined frequency, showing privileges reviewed and reevaluated · Cloud console / configuration management
- Records of privileges removed or reduced as a result of a review · Cloud console / configuration management
governing documentDocuments that govern the control
- Documented list of privileges that permit change to system components and system related information in the production or operational environment · Policy repository / GRC workspace
First move
Start with the 2 of 5 artefacts that already live in a system (Identity provider / directory); keep the periodic reviews but log each one as a dated record with a named reviewer.
Common gaps auditors find
- Break glass and deployment service accounts excluded from the review, though they carry the strongest change privilege
- Review confirms the list is unchanged rather than reevaluating whether each privilege is still justified
- Change privilege limited in the application while underlying platform, container or infrastructure as code paths remain open
Do this for your whole sheet
Paste the rows you run your controls from and get this mapping for every control at once, with the periodic-review ones flagged and a first move per row. No account for the first run.
Build my evidence sheetCM-5(1) Access Restrictions for Change | Automated Access Enforcement and Audit Records. (a) Enforce access restrictions using [Assignment: organization-defined automated mechanisms]; and (b) Automatically generate audit records of the enforcement actions · CM-6 Configuration Settings