SOX Change Log Checker
Framework

NIST SP 800-53 Rev 5: what it asks of a production change

For a federal customer, NIST SP 800-53 Rev 5 carries configuration change control (CM-3), impact analysis (CM-4), access restrictions for change (CM-5), the configuration management plan (CM-9), separation of duties (AC-5) and the developer controls (SA-10, SA-11), with integrity monitoring in SI-7.

Our statement of each clause, read against the copy we hold and cited to it; it is not the instrument's verbatim wording.

The findings it sits behind

8 clauses cited
FindingClause
No independent approvalSP 800-53 CM-3
Approved after it shippedSP 800-53 CM-3 · SP 800-53 CM-4
Automated author, no human approvalSP 800-53 SA-10 · SP 800-53 CM-3
Deployed their own changeSP 800-53 CM-5 · SP 800-53 AC-5
One person, three rolesSP 800-53 AC-5 · SP 800-53 CM-5
Emergency, no approval afterSP 800-53 CM-3
Deployment with no matching changeSP 800-53 SI-7 · SP 800-53 CM-5
No ticket referenceSP 800-53 CM-3 · SP 800-53 CM-9
Approver not on the listSP 800-53 CM-5 · SP 800-53 CM-9
No test evidenceSP 800-53 SA-11 · SP 800-53 CM-4

Every NIST SP 800-53 Rev 5 clause the checker cites

Run the specimen Check your own change log