Cyber Resilience

NIST 800-53 r5 · Controls catalogue · Family CM

CM-5Access Restrictions for Change

Define, document, approve, and enforce physical and logical access restrictions associated with changes to the system.

Last updated: 22 August 2026 07:11 UTC

Implementations targeting this control (0)

ATT&CK techniques this control mitigates (160)

Weaknesses this control addresses (8)AI-assisted

CWEs ranked by how often they appear in real CVEs. The rationale describes how this control reduces exploitability of each weakness class.

CWE Name CVEs Why this control addresses it
CWE-862Missing Authorization10,200+Mandating authorization for changes prevents missing authorization checks on critical modification functions.
CWE-284Improper Access Control6,900+Enforcing physical and logical access restrictions for system changes directly prevents unauthorized actors from modifying the system.
CWE-863Incorrect Authorization3,900+The control requires correct implementation of authorization specifically tied to change operations.
CWE-269Improper Privilege Management3,400+Restricting who can perform changes helps ensure privileges are managed properly rather than assigned broadly.
CWE-732Incorrect Permission Assignment for Critical Resource1,900+Defining and enforcing access restrictions ensures correct permission assignments on resources that support changes.
CWE-285Improper Authorization1,500+Requiring definition, approval, and enforcement of access rules for changes addresses improper authorization of modifications.
CWE-250Execution with Unnecessary Privileges300+Limiting change access to only approved entities reduces the risk of unnecessary privileges being available for modifications.
CWE-15External Control of System or Configuration Setting76Restricting changes to system and configuration settings prevents external entities from controlling those settings without approval.

Top CVEs where this control is the strongest mitigation

CVE Risk CVSS EPSS Match
CVE-2025-212835.46.50.0147good
CVE-2026-41176 8.99.80.3271good
CVE-2024-39280 8.09.10.3417good
CVE-2026-45087 7.710.00.0147good
CVE-2024-38666 7.69.10.1888good
CVE-2024-4326 7.59.80.0097good
CVE-2024-51544 7.38.20.1352good
CVE-2026-22708 7.39.80.0056good
CVE-2024-10979 7.18.80.0439good
CVE-2026-44774 7.09.90.0047good
CVE-2026-46399 7.09.40.0029good
CVE-2024-39602 6.89.10.0231good
CVE-2024-39788 6.79.10.0151good
CVE-2024-39790 6.79.10.0151good
CVE-2024-39793 6.79.10.0151good
CVE-2024-39795 6.79.10.0151good
CVE-2024-39798 6.79.10.0186good
CVE-2024-39799 6.79.10.0130good
CVE-2024-39800 6.79.10.0186good
CVE-2024-39789 6.69.10.0106good
CVE-2024-39794 6.69.10.0106good
CVE-2024-51543 6.28.20.0034good
CVE-2026-27203 6.28.30.0036good
CVE-2026-1784 6.08.80.0019good
CVE-2026-41489 5.98.80.0013good

Other controls in family CM

CM-1 CM-10 CM-11 CM-12 CM-13 CM-14 CM-2 CM-3 CM-4 CM-6 CM-7 CM-8 CM-9