Independent DIB implementation resource — not affiliated with or endorsed by the U.S. Department of WarView the official DoW campaign ↗
03.04.03OFFICIAL TITLEPENDING NIST SME REVIEW

03.04.03Configuration Change Control

03.04 Configuration Management · NIST SP 800-171 Rev. 3

Independent summary of the official requirement

Requires defining the types of system changes that are configuration-controlled; reviewing proposed configuration-controlled changes and approving or disapproving them with explicit consideration of security impacts; implementing and documenting approved changes; and monitoring and reviewing activities associated with those changes.

Rev. 3 requirement text is multi-part and parameterized with organization-defined values, so this site summarizes rather than reproduces it. The summary is independent — read the official publication for the binding wording.

NIST SP 800-171 Rev. 3 — Protecting CUI in Nonfederal SystemsNIST SP 800-171A Rev. 3 — Assessing Security Requirements for CUI
Independent interpretation

What this requirement is after

Changes to systems go through a gate: the organization decides which kinds of change need control, reviews proposals with security explicitly on the table, records what was approved and what was done, and looks back at change activity. The alternative is the Friday-afternoon change nobody can explain in Monday's incident.

Across revisions

Carried from 3.4.3 and expanded: defining which change types are configuration-controlled, and monitoring and reviewing change activity, are now explicit parts.

Mapped practices

Brilliant at the Basics practices that support this requirement

Partial implementation supportModerate confidence

Why: Reviewing, approving, documenting, and auditing every OT change — including vendor-performed ones — is this requirement's discipline practiced where it is hardest to sustain. The practice's change records are configuration change control operating, for the estate it covers.

What this does not claim: May partially address the requirement, and only for the OT estate — enterprise IT changes inside the CUI boundary need their own change process, and that is where most of a defense contractor's boundary usually sits. Defining which change types are configuration-controlled system-wide, and monitoring change activity beyond OT, remain separate work.

Practice-side activities
  • Route OT changes through combined safety-and-security review with named approvers
  • Capture emergency changes and review them after the fact
  • Audit change records against observed reality on a cadence
Evidence this produces
  • Completed OT change records with approvals and testing
  • Emergency-change closure reviews
  • Periodic change-record audits

Where this holds: Holds for OT within the assessed boundary; the enterprise side of the requirement is untouched by this practice.

Review status: Pending NIST SME review · Reviewed by Brilliant at the Basics editorial — practitioner-authored; NIST SME review pending · updated 2026-08-06

Doing the work

Implementation considerations and evidence

Implementation considerationsIndependent guidance — tailor to your environment
  • Define the controlled change types first — firewall rules, identity configuration, server builds, security tooling — so routine desktop work does not drown the process.
  • A lightweight ticket with a security-impact field, a named approver, and a record of what was actually done carries this at small scale; ceremony is not the requirement.
  • Review the change log periodically against reality — an unrecorded change found by drift detection or audit is the finding.
What operating evidence looks likeRecords worth retaining, not a submission checklist
  • The documented controlled-change types and process
  • Sampled change records showing review, security consideration, approval, and implementation
  • A periodic change-activity review record

Suggested owners, derived from the mapped practices and artifacts: Plant / OT leader · IT leader. Ownership is a named person in your organization, not a role on a website.

Artifacts

Templates and worksheets with a mapped relationship

The other revision

Where this came from in Rev. 2

Provenance

Sources and review status

Primary sourcesNIST SP 800-171 Rev. 3 — Protecting CUI in Nonfederal Systems · NIST SP 800-171A Rev. 3 — Assessing Security Requirements for CUI
Review statusPending NIST SME review
Content version1.0
Updated