CM-5 Configuration Management

Access Restrictions for Change

High Risk Moderate Low Cost

CM-5 requires defining, documenting, approving, and enforcing physical and logical access restrictions associated with changes to the system. If every helpdesk tech can alter EHR security roles or firewall rules, CM-3 paperwork cannot prevent harmful configuration drift or malicious change. Healthcare needs tight change permissions on identity, EHR admin, interface engines, and boundary devices.

Control Objective

Ensure only authorized, dual-controlled where needed, personnel can implement configuration changes on systems that affect ePHI — with enforcement technically and physically.

Implementation Guidance

  1. Inventory change-capable roles: EHR security, interface admins, domain/cloud admins, firewall, endpoint management, biomed device managers.
  2. Apply least privilege and separation of duties (requestor vs approver vs implementer where feasible).
  3. Use privileged access workstations / just-in-time elevation for production changes.
  4. Enforce MFA and named accounts — no shared change passwords.
  5. Restrict physical access to data centers and network closets that enable console changes (PE-2/PE-3).
  6. Log and review privileged change actions (AU-2/AU-6).
  7. Remove change rights promptly on transfer/termination (PS-4/PS-5).
  8. Periodically recertify who holds production change roles.

Real-World Use Cases

How this control shows up in healthcare and HIPAA-covered environments.

Helpdesk over-privilege

Tier-1 techs inherit EHR security console rights from a legacy template. CM-5 remediation splits security admin from password reset roles — reducing unauthorized role grants.

Dual control on firewall changes

Production firewall pushes require a second approver in the PAN/change tool, preventing a single engineer from opening vendor any-any rules alone.

Contractor interface access

Vendor mapper receives time-boxed change rights for a cutover weekend; rights auto-expire Monday — CM-5 enforcement beyond the ticket narrative.

Best Practices

  • Least privilege for change roles.
  • JIT elevation over standing admin.
  • Separation of duties on high-risk systems.
  • Physical + logical restrictions.
  • Recertify change permissions quarterly.
  • Full audit trail of privileged changes.

Common Gaps & Violations

  • Broad Domain Admins used for routine EHR tweaks.
  • Shared break-glass passwords for change windows.
  • Contractors with permanent change rights.
  • No review of who can modify security groups.
  • Console access in unlocked network closets.

Required Documentation

  • Access restrictions for change procedure
  • Inventories of change-capable roles
  • Approval / SoD matrices
  • Privileged access provisioning evidence
  • Periodic access recertification records

How to Test & Validate

  1. Sample users with EHR security or firewall change rights for authorization evidence.
  2. Confirm SoD or dual control on a high-risk change path.
  3. Verify JIT/standing privilege posture matches policy.
  4. Check recent terminations no longer hold change roles.
  5. Review physical access lists for console-capable areas.

Audit Considerations

Assessors compare who can change production to who should. Excessive change privileges are treated as both CM-5 and access-control failures.

HIPAA Mapping

How this NIST control supports HIPAA Security Rule expectations.

  • 164.312(a) Access Control — unique users and appropriate access include who may change security-relevant settings.
  • 164.308(a)(4) Information Access Management — isolate and control access to ePHI; change rights are high-impact access.
  • 164.308(a)(3) Workforce Security — supervision and authorization for workforce who can alter systems.
  • 164.310(a) Facility Access Controls — physical access enabling system changes must be controlled.

Compliance Tips

  • Maintain a short list of production change roles and owners.
  • Prefer group-based rights with ticketed membership changes.
  • Alert on direct grants of EHR security admin outside the IAM process.

Frequently Asked Questions

Is CM-5 only about software deployment tools?

No. It covers logical and physical restrictions associated with making changes — including consoles, cloud portals, and facilities.

How does CM-5 relate to AC-6?

AC-6 is least privilege broadly; CM-5 focuses that principle on permissions that enable configuration change.

Do emergency accounts violate CM-5?

Break-glass accounts can exist if tightly controlled, monitored, and reviewed — not as daily shared change credentials.

References & Resources

  • NIST SP 800-53 Rev. 5 — CM-5
  • Related controls: CM-3, AC-2, AC-3, AC-5, AC-6, AU-2, PE-3

Need Help Implementing CM-5?

Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.