CMMCpedia Download

Requirements / Configuration Management (CM)

CM.L2-3.4.5

Access Restrictions for Change

Official Source Material

Define, document, approve, and enforce physical and logical access restrictions associated with changes to organizational systems.

Determine if:

  1. [a] physical access restrictions associated with changes to the system are defined;
  2. [b] physical access restrictions associated with changes to the system are documented;
  3. [c] physical access restrictions associated with changes to the system are approved;
  4. [d] physical access restrictions associated with changes to the system are enforced;
  5. [e] logical access restrictions associated with changes to the system are defined;
  6. [f] logical access restrictions associated with changes to the system are documented;
  7. [g] logical access restrictions associated with changes to the system are approved; and
  8. [h] logical access restrictions associated with changes to the system are enforced.

Source: CMMC Assessment Guide - Level 2, Version 2.13, September 2024

Practitioner Guidance

How to meet it

This requirement restricts who can make changes, not how changes are approved.

CM.L2-3.4.3 governs the change process. This one asks who can physically reach the equipment and who holds credentials that can alter it. The eight objectives are a grid: physical restrictions in [a] through [d] and logical restrictions in [e] through [h], each defined, documented, approved, and enforced.

Logical restriction is the short list of people with administrative rights.

Name the people authorized to change systems, give only them administrative credentials, and keep everyone else a standard user. Put the named list in the system security plan, the document that describes how your system meets each requirement, or in a procedure. That covers [e] and [f]. A manager's sign-off on the list covers [g], and the directory enforcing it covers [h].

Physical restriction is a locked room and a list of key holders.

Servers and network gear live behind a locked door, and you can name who holds the key or badge. That covers [a] through [d] for a small office. Badge logs where they exist. A documented key list and a sign-in sheet where they do not.

Let the change management process carry this when it names the restrictions.

State three things in the system security plan: changes follow the CM.L2-3.4.3 process, systems sit in access-controlled rooms, and only named administrators hold change credentials. That answers all eight objectives without a separate program.

Fully remote companies answer the physical half through inheritance and policy.

Infrastructure in a FedRAMP-authorized cloud, one the federal government has assessed and approved, inherits the provider's physical controls. Document the inheritance. Home offices are covered by a remote work policy: a locked door, the screen positioned against shoulder surfing, the laptop secured when not in use.

What falls short

  • Local administrator rights for the general user population. When everyone can change the system, logical restrictions are neither defined nor enforced, which fails [e] and [h].

Edge cases

  • You define which changes the restrictions cover. Scope them to baseline and security-relevant changes so a user changing a desktop theme does not violate your own document.
  • An outside technician making an approved change works under the same restrictions: escorted physical access, a temporary credential scoped to the task, and both removed when the work is verified.

CMMCpedia is independently maintained and is not affiliated with the U.S. Department of Defense. The content is educational. It is not legal advice, and it does not guarantee certification.