Browse 1,193 controls and enhancements across 20 security and privacy families. Use the GovRAMP crosswalk to locate controls referenced by Security Snapshot, Core, and Moderate.
A shared catalog supports common-control planning; designation as a common, hybrid, or system-specific control depends on your organization’s implementation and inheritance decisions.
Sources and crosswalk scope
NIST OSCAL content 5.1.1+u4, retrieved 2026-09-18. GovRAMP Snapshot v1.4 and Core selection from Moderate v1.06 reference the December 2020 Rev. 5 text. Mappings establish exact identifier correspondence, not identical requirements, inherited implementation, or GovRAMP authorization. GovRAMP parameters and additional requirements remain authoritative for each program. Full Moderate, High, and other programs are not mapped here. Withdrawn controls are retained for reference.
Official pinned NIST sourceSHA-256: 81cf2de45ede9aef3de7ce09d65ea9d32f662c483bbf916f6e346292b22f7763
Assessment, Authorization, and Monitoring · Base control
CA-9 · Internal System Connections
Control statement and discussion
NIST control statement
a. Authorize internal connections of [Assignment: system components] to the system;
b. Document, for each internal connection, the interface characteristics, security and privacy requirements, and the nature of the information communicated;
c. Terminate internal system connections after [Assignment: conditions] ; and
d. Review [Assignment: frequency] the continued need for each internal connection.
Discussion
Internal system connections are connections between organizational systems and separate constituent system components (i.e., connections between components that are part of the same system) including components used for system development. Intra-system connections include connections with mobile devices, notebook and desktop computers, tablets, printers, copiers, facsimile machines, scanners, sensors, and servers. Instead of authorizing each internal system connection individually, organizations can authorize internal connections for a class of system components with common characteristics and/or configurations, including printers, scanners, and copiers with a specified processing, transmission, and storage capability or smart phones and tablets with a specific baseline configuration. The continued need for an internal system connection is reviewed from the perspective of whether it provides support for organizational missions or business functions.
GovRAMP crosswalk
- GovRAMP Moderate Readiness · CA-9 — Direct NIST identifier reference. GovRAMP source matrix
Assessment, Authorization, and Monitoring · Enhancement
CA-9(1) · Compliance Checks
View parent controlControl statement and discussion
NIST control statement
Perform security and privacy compliance checks on constituent system components prior to the establishment of the internal connection.
Discussion
Compliance checks include verification of the relevant baseline configuration.
GovRAMP crosswalk
Not selected in the imported Snapshot or Core sets. This does not establish exclusion from other GovRAMP baselines.
Configuration Management · Base control
CM-1 · Policy and Procedures
Control statement and discussion
NIST control statement
a. Develop, document, and disseminate to [Assignment: organization-defined personnel or roles]:
1. [Selection (one-or-more): organization-level; mission/business process-level; system-level] configuration management policy that:
(a) Addresses purpose, scope, roles, responsibilities, management commitment, coordination among organizational entities, and compliance; and
(b) Is consistent with applicable laws, executive orders, directives, regulations, policies, standards, and guidelines; and
2. Procedures to facilitate the implementation of the configuration management policy and the associated configuration management controls;
b. Designate an [Assignment: official] to manage the development, documentation, and dissemination of the configuration management policy and procedures; and
c. Review and update the current configuration management:
1. Policy [Assignment: frequency] and following [Assignment: events] ; and
2. Procedures [Assignment: frequency] and following [Assignment: events].
Discussion
Configuration management policy and procedures address the controls in the CM family that are implemented within systems and organizations. The risk management strategy is an important factor in establishing such policies and procedures. Policies and procedures contribute to security and privacy assurance. Therefore, it is important that security and privacy programs collaborate on the development of configuration management policy and procedures. Security and privacy program policies and procedures at the organization level are preferable, in general, and may obviate the need for mission- or system-specific policies and procedures. The policy can be included as part of the general security and privacy policy or be represented by multiple policies that reflect the complex nature of organizations. Procedures can be established for security and privacy programs, for mission/business processes, and for systems, if needed. Procedures describe how the policies or controls are implemented and can be directed at the individual or role that is the object of the procedure. Procedures can be documented in system security and privacy plans or in one or more separate documents. Events that may precipitate an update to configuration management policy and procedures include, but are not limited to, assessment or audit findings, security incidents or breaches, or changes in applicable laws, executive orders, directives, regulations, policies, standards, and guidelines. Simply restating controls does not constitute an organizational policy or procedure.
GovRAMP crosswalk
- GovRAMP Moderate Readiness · CM-1 — Direct NIST identifier reference. GovRAMP source matrix
Configuration Management · Base control
CM-2 · Baseline Configuration
Control statement and discussion
NIST control statement
a. Develop, document, and maintain under configuration control, a current baseline configuration of the system; and
b. Review and update the baseline configuration of the system:
1. [Assignment: frequency];
2. When required due to [Assignment: circumstances] ; and
3. When system components are installed or upgraded.
Discussion
Baseline configurations for systems and system components include connectivity, operational, and communications aspects of systems. Baseline configurations are documented, formally reviewed, and agreed-upon specifications for systems or configuration items within those systems. Baseline configurations serve as a basis for future builds, releases, or changes to systems and include security and privacy control implementations, operational procedures, information about system components, network topology, and logical placement of components in the system architecture. Maintaining baseline configurations requires creating new baselines as organizational systems change over time. Baseline configurations of systems reflect the current enterprise architecture.
GovRAMP crosswalk
- GovRAMP Security Snapshot Readiness · CM-2 — Direct NIST identifier reference. GovRAMP source matrix
- GovRAMP Core Readiness — 60 Controls · CM-2 — Direct NIST identifier reference. GovRAMP source matrix
- GovRAMP Moderate Readiness · CM-2 — Direct NIST identifier reference. GovRAMP source matrix
Configuration Management · Enhancement
CM-2(2) · Automation Support for Accuracy and Currency
View parent controlControl statement and discussion
NIST control statement
Maintain the currency, completeness, accuracy, and availability of the baseline configuration of the system using [Assignment: automated mechanisms].
Discussion
Automated mechanisms that help organizations maintain consistent baseline configurations for systems include configuration management tools, hardware, software, firmware inventory tools, and network management tools. Automated tools can be used at the organization level, mission and business process level, or system level on workstations, servers, notebook computers, network components, or mobile devices. Tools can be used to track version numbers on operating systems, applications, types of software installed, and current patch levels. Automation support for accuracy and currency can be satisfied by the implementation of [CM-8(2)](#cm-8.2) for organizations that combine system component inventory and baseline configuration activities.
GovRAMP crosswalk
- GovRAMP Security Snapshot Readiness · CM-2 (2) — Direct NIST identifier reference. GovRAMP source matrix
- GovRAMP Core Readiness — 60 Controls · CM-2 (2) — Direct NIST identifier reference. GovRAMP source matrix
- GovRAMP Moderate Readiness · CM-2 (2) — Direct NIST identifier reference. GovRAMP source matrix
Configuration Management · Enhancement
CM-2(3) · Retention of Previous Configurations
View parent controlControl statement and discussion
NIST control statement
Retain [Assignment: number] of previous versions of baseline configurations of the system to support rollback.
Discussion
Retaining previous versions of baseline configurations to support rollback include hardware, software, firmware, configuration files, configuration records, and associated documentation.
GovRAMP crosswalk
- GovRAMP Moderate Readiness · CM-2 (3) — Direct NIST identifier reference. GovRAMP source matrix
Configuration Management · Enhancement
CM-2(6) · Development and Test Environments
View parent controlControl statement and discussion
NIST control statement
Maintain a baseline configuration for system development and test environments that is managed separately from the operational baseline configuration.
Discussion
Establishing separate baseline configurations for development, testing, and operational environments protects systems from unplanned or unexpected events related to development and testing activities. Separate baseline configurations allow organizations to apply the configuration management that is most appropriate for each type of configuration. For example, the management of operational configurations typically emphasizes the need for stability, while the management of development or test configurations requires greater flexibility. Configurations in the test environment mirror configurations in the operational environment to the extent practicable so that the results of the testing are representative of the proposed changes to the operational systems. Separate baseline configurations do not necessarily require separate physical environments.
GovRAMP crosswalk
Not selected in the imported Snapshot or Core sets. This does not establish exclusion from other GovRAMP baselines.
Configuration Management · Enhancement
CM-2(7) · Configure Systems and Components for High-risk Areas
View parent controlControl statement and discussion
NIST control statement
(a) Issue [Assignment: systems or system components] with [Assignment: configurations] to individuals traveling to locations that the organization deems to be of significant risk; and
(b) Apply the following controls to the systems or components when the individuals return from travel: [Assignment: controls].
Discussion
When it is known that systems or system components will be in high-risk areas external to the organization, additional controls may be implemented to counter the increased threat in such areas. For example, organizations can take actions for notebook computers used by individuals departing on and returning from travel. Actions include determining the locations that are of concern, defining the required configurations for the components, ensuring that components are configured as intended before travel is initiated, and applying controls to the components after travel is completed. Specially configured notebook computers include computers with sanitized hard drives, limited applications, and more stringent configuration settings. Controls applied to mobile devices upon return from travel include examining the mobile device for signs of physical tampering and purging and reimaging disk drives. Protecting information that resides on mobile devices is addressed in the [MP](#mp) (Media Protection) family.
GovRAMP crosswalk
- GovRAMP Moderate Readiness · CM-2 (7) — Direct NIST identifier reference. GovRAMP source matrix
Configuration Management · Base control
CM-3 · Configuration Change Control
Control statement and discussion
NIST control statement
a. Determine and document the types of changes to the system that are configuration-controlled;
b. Review proposed configuration-controlled changes to the system and approve or disapprove such changes with explicit consideration for security and privacy impact analyses;
c. Document configuration change decisions associated with the system;
d. Implement approved configuration-controlled changes to the system;
e. Retain records of configuration-controlled changes to the system for [Assignment: time period];
f. Monitor and review activities associated with configuration-controlled changes to the system; and
g. Coordinate and provide oversight for configuration change control activities through [Assignment: configuration change control element] that convenes [Selection (one-or-more): [Assignment: frequency] ; when [Assignment: configuration change conditions] ].
Discussion
Configuration change control for organizational systems involves the systematic proposal, justification, implementation, testing, review, and disposition of system changes, including system upgrades and modifications. Configuration change control includes changes to baseline configurations, configuration items of systems, operational procedures, configuration settings for system components, remediate vulnerabilities, and unscheduled or unauthorized changes. Processes for managing configuration changes to systems include Configuration Control Boards or Change Advisory Boards that review and approve proposed changes. For changes that impact privacy risk, the senior agency official for privacy updates privacy impact assessments and system of records notices. For new systems or major upgrades, organizations consider including representatives from the development organizations on the Configuration Control Boards or Change Advisory Boards. Auditing of changes includes activities before and after changes are made to systems and the auditing activities required to implement such changes. See also [SA-10](#sa-10).
GovRAMP crosswalk
- GovRAMP Moderate Readiness · CM-3 — Direct NIST identifier reference. GovRAMP source matrix
Configuration Management · Enhancement
CM-3(1) · Automated Documentation, Notification, and Prohibition of Changes
View parent controlControl statement and discussion
NIST control statement
Use [Assignment: automated mechanisms] to:
(a) Document proposed changes to the system;
(b) Notify [Assignment: approval authorities] of proposed changes to the system and request change approval;
(c) Highlight proposed changes to the system that have not been approved or disapproved within [Assignment: time period];
(d) Prohibit changes to the system until designated approvals are received;
(e) Document all changes to the system; and
(f) Notify [Assignment: personnel] when approved changes to the system are completed.
Discussion
None.
GovRAMP crosswalk
Not selected in the imported Snapshot or Core sets. This does not establish exclusion from other GovRAMP baselines.
Configuration Management · Enhancement
CM-3(2) · Testing, Validation, and Documentation of Changes
View parent controlControl statement and discussion
NIST control statement
Test, validate, and document changes to the system before finalizing the implementation of the changes.
Discussion
Changes to systems include modifications to hardware, software, or firmware components and configuration settings defined in [CM-6](#cm-6) . Organizations ensure that testing does not interfere with system operations that support organizational mission and business functions. Individuals or groups conducting tests understand security and privacy policies and procedures, system security and privacy policies and procedures, and the health, safety, and environmental risks associated with specific facilities or processes. Operational systems may need to be taken offline, or replicated to the extent feasible, before testing can be conducted. If systems must be taken offline for testing, the tests are scheduled to occur during planned system outages whenever possible. If the testing cannot be conducted on operational systems, organizations employ compensating controls.
GovRAMP crosswalk
- GovRAMP Moderate Readiness · CM-3 (2) — Direct NIST identifier reference. GovRAMP source matrix
Configuration Management · Enhancement
CM-3(3) · Automated Change Implementation
View parent controlControl statement and discussion
NIST control statement
Implement changes to the current system baseline and deploy the updated baseline across the installed base using [Assignment: automated mechanisms].
Discussion
Automated tools can improve the accuracy, consistency, and availability of configuration baseline information. Automation can also provide data aggregation and data correlation capabilities, alerting mechanisms, and dashboards to support risk-based decision-making within the organization.
GovRAMP crosswalk
Not selected in the imported Snapshot or Core sets. This does not establish exclusion from other GovRAMP baselines.
Configuration Management · Enhancement
CM-3(4) · Security and Privacy Representatives
View parent controlControl statement and discussion
NIST control statement
Require [Assignment: organization-defined security and privacy representatives] to be members of the [Assignment: configuration change control element].
Discussion
Information security and privacy representatives include system security officers, senior agency information security officers, senior agency officials for privacy, or system privacy officers. Representation by personnel with information security and privacy expertise is important because changes to system configurations can have unintended side effects, some of which may be security- or privacy-relevant. Detecting such changes early in the process can help avoid unintended, negative consequences that could ultimately affect the security and privacy posture of systems. The configuration change control element referred to in the second organization-defined parameter reflects the change control elements defined by organizations in [CM-3g](#cm-3_smt.g).
GovRAMP crosswalk
- GovRAMP Moderate Readiness · CM-3 (4) — Direct NIST identifier reference. GovRAMP source matrix
Configuration Management · Enhancement
CM-3(5) · Automated Security Response
View parent controlControl statement and discussion
NIST control statement
Implement the following security responses automatically if baseline configurations are changed in an unauthorized manner: [Assignment: security responses].
Discussion
Automated security responses include halting selected system functions, halting system processing, and issuing alerts or notifications to organizational personnel when there is an unauthorized modification of a configuration item.
GovRAMP crosswalk
Not selected in the imported Snapshot or Core sets. This does not establish exclusion from other GovRAMP baselines.
Configuration Management · Enhancement
CM-3(6) · Cryptography Management
View parent controlControl statement and discussion
NIST control statement
Ensure that cryptographic mechanisms used to provide the following controls are under configuration management: [Assignment: controls].
Discussion
The controls referenced in the control enhancement refer to security and privacy controls from the control catalog. Regardless of the cryptographic mechanisms employed, processes and procedures are in place to manage those mechanisms. For example, if system components use certificates for identification and authentication, a process is implemented to address the expiration of those certificates.
GovRAMP crosswalk
Not selected in the imported Snapshot or Core sets. This does not establish exclusion from other GovRAMP baselines.
Configuration Management · Enhancement
CM-3(7) · Review System Changes
View parent controlControl statement and discussion
NIST control statement
Review changes to the system [Assignment: frequency] or when [Assignment: circumstances] to determine whether unauthorized changes have occurred.
Discussion
Indications that warrant a review of changes to the system and the specific circumstances justifying such reviews may be obtained from activities carried out by organizations during the configuration change process or continuous monitoring process.
GovRAMP crosswalk
Not selected in the imported Snapshot or Core sets. This does not establish exclusion from other GovRAMP baselines.
Configuration Management · Enhancement
CM-3(8) · Prevent or Restrict Configuration Changes
View parent controlControl statement and discussion
NIST control statement
Prevent or restrict changes to the configuration of the system under the following circumstances: [Assignment: circumstances].
Discussion
System configuration changes can adversely affect critical system security and privacy functionality. Change restrictions can be enforced through automated mechanisms.
GovRAMP crosswalk
Not selected in the imported Snapshot or Core sets. This does not establish exclusion from other GovRAMP baselines.
Configuration Management · Base control
CM-4 · Impact Analyses
Control statement and discussion
NIST control statement
Analyze changes to the system to determine potential security and privacy impacts prior to change implementation.
Discussion
Organizational personnel with security or privacy responsibilities conduct impact analyses. Individuals conducting impact analyses possess the necessary skills and technical expertise to analyze the changes to systems as well as the security or privacy ramifications. Impact analyses include reviewing security and privacy plans, policies, and procedures to understand control requirements; reviewing system design documentation and operational procedures to understand control implementation and how specific system changes might affect the controls; reviewing the impact of changes on organizational supply chain partners with stakeholders; and determining how potential changes to a system create new risks to the privacy of individuals and the ability of implemented controls to mitigate those risks. Impact analyses also include risk assessments to understand the impact of the changes and determine if additional controls are required.
GovRAMP crosswalk
- GovRAMP Security Snapshot Readiness · CM-4 — Direct NIST identifier reference. GovRAMP source matrix
- GovRAMP Core Readiness — 60 Controls · CM-4 — Direct NIST identifier reference. GovRAMP source matrix
- GovRAMP Moderate Readiness · CM-4 — Direct NIST identifier reference. GovRAMP source matrix
Configuration Management · Enhancement
CM-4(1) · Separate Test Environments
View parent controlControl statement and discussion
NIST control statement
Analyze changes to the system in a separate test environment before implementation in an operational environment, looking for security and privacy impacts due to flaws, weaknesses, incompatibility, or intentional malice.
Discussion
A separate test environment requires an environment that is physically or logically separate and distinct from the operational environment. The separation is sufficient to ensure that activities in the test environment do not impact activities in the operational environment and that information in the operational environment is not inadvertently transmitted to the test environment. Separate environments can be achieved by physical or logical means. If physically separate test environments are not implemented, organizations determine the strength of mechanism required when implementing logical separation.
GovRAMP crosswalk
Not selected in the imported Snapshot or Core sets. This does not establish exclusion from other GovRAMP baselines.
Configuration Management · Enhancement
CM-4(2) · Verification of Controls
View parent controlControl statement and discussion
NIST control statement
After system changes, verify that the impacted controls are implemented correctly, operating as intended, and producing the desired outcome with regard to meeting the security and privacy requirements for the system.
Discussion
Implementation in this context refers to installing changed code in the operational system that may have an impact on security or privacy controls.
GovRAMP crosswalk
- GovRAMP Moderate Readiness · CM-4 (2) — Direct NIST identifier reference. GovRAMP source matrix
Configuration Management · Base control
CM-5 · Access Restrictions for Change
Control statement and discussion
NIST control statement
Define, document, approve, and enforce physical and logical access restrictions associated with changes to the system.
Discussion
Changes to the hardware, software, or firmware components of systems or the operational procedures related to the system can potentially have significant effects on the security of the systems or individuals’ privacy. Therefore, organizations permit only qualified and authorized individuals to access systems for purposes of initiating changes. Access restrictions include physical and logical access controls (see [AC-3](#ac-3) and [PE-3](#pe-3) ), software libraries, workflow automation, media libraries, abstract layers (i.e., changes implemented into external interfaces rather than directly into systems), and change windows (i.e., changes occur only during specified times).
GovRAMP crosswalk
- GovRAMP Security Snapshot Readiness · CM-5 — Direct NIST identifier reference. GovRAMP source matrix
- GovRAMP Core Readiness — 60 Controls · CM-5 — Direct NIST identifier reference. GovRAMP source matrix
- GovRAMP Moderate Readiness · CM-5 — Direct NIST identifier reference. GovRAMP source matrix
Configuration Management · Enhancement
CM-5(1) · Automated Access Enforcement and Audit Records
View parent controlControl statement and discussion
NIST control statement
(a) Enforce access restrictions using [Assignment: automated mechanisms] ; and
(b) Automatically generate audit records of the enforcement actions.
Discussion
Organizations log system accesses associated with applying configuration changes to ensure that configuration change control is implemented and to support after-the-fact actions should organizations discover any unauthorized changes.
GovRAMP crosswalk
- GovRAMP Security Snapshot Readiness · CM-5 (1) — Direct NIST identifier reference. GovRAMP source matrix
- GovRAMP Core Readiness — 60 Controls · CM-5 (1) — Direct NIST identifier reference. GovRAMP source matrix
- GovRAMP Moderate Readiness · CM-5 (1) — Direct NIST identifier reference. GovRAMP source matrix
Configuration Management · Enhancement
CM-5(4) · Dual Authorization
View parent controlControl statement and discussion
NIST control statement
Enforce dual authorization for implementing changes to [Assignment: organization-defined system components and system-level information].
Discussion
Organizations employ dual authorization to help ensure that any changes to selected system components and information cannot occur unless two qualified individuals approve and implement such changes. The two individuals possess the skills and expertise to determine if the proposed changes are correct implementations of approved changes. The individuals are also accountable for the changes. Dual authorization may also be known as two-person control. To reduce the risk of collusion, organizations consider rotating dual authorization duties to other individuals. System-level information includes operational procedures.
GovRAMP crosswalk
Not selected in the imported Snapshot or Core sets. This does not establish exclusion from other GovRAMP baselines.
Configuration Management · Enhancement
CM-5(5) · Privilege Limitation for Production and Operation
View parent controlControl statement and discussion
NIST control statement
(a) Limit privileges to change system components and system-related information within a production or operational environment; and
(b) Review and reevaluate privileges [Assignment: organization-defined frequency].
Discussion
In many organizations, systems support multiple mission and business functions. Limiting privileges to change system components with respect to operational systems is necessary because changes to a system component may have far-reaching effects on mission and business processes supported by the system. The relationships between systems and mission/business processes are, in some cases, unknown to developers. System-related information includes operational procedures.
GovRAMP crosswalk
- GovRAMP Security Snapshot Readiness · CM-5 (5) — Direct NIST identifier reference. GovRAMP source matrix
- GovRAMP Core Readiness — 60 Controls · CM-5 (5) — Direct NIST identifier reference. GovRAMP source matrix
- GovRAMP Moderate Readiness · CM-5 (5) — Direct NIST identifier reference. GovRAMP source matrix
Configuration Management · Enhancement
CM-5(6) · Limit Library Privileges
View parent controlControl statement and discussion
NIST control statement
Limit privileges to change software resident within software libraries.
Discussion
Software libraries include privileged programs.
GovRAMP crosswalk
Not selected in the imported Snapshot or Core sets. This does not establish exclusion from other GovRAMP baselines.