NIST 800-171 · Configuration Management
Requirement 3.4.5
- SPRS weight
- SPRS weight: 5
- POA&M eligibility
- Not POA&M-eligible
- Assessment objectives
- 8 assessment objectives
Official requirement text
Define, document, approve, and enforce physical and logical access restrictions associated with changes to organizational systems.
Assessment objectives
Assessors don’t evaluate the requirement as one sentence; they walk these objectives one by one. Each must be met for the requirement to score.
- 3.4.5[a]physical access restrictions associated with changes to the system are defined.
- 3.4.5[b]physical access restrictions associated with changes to the system are documented.
- 3.4.5[c]physical access restrictions associated with changes to the system are approved.
- 3.4.5[d]physical access restrictions associated with changes to the system are enforced.
- 3.4.5[e]logical access restrictions associated with changes to the system are defined.
- 3.4.5[f]logical access restrictions associated with changes to the system are documented.
- 3.4.5[g]logical access restrictions associated with changes to the system are approved.
- 3.4.5[h]logical access restrictions associated with changes to the system are enforced.
Inside Valontir, this requirement carries a full plain-English guide: what it asks in normal words, what good looks like in a small shop, the evidence an assessor accepts, the common gaps that cost points, and a plain reading of every assessment objective shown above. See it in a demo.