Why: Reviewing, approving, documenting, and auditing every OT change — including vendor-performed ones — is this requirement's discipline practiced where it is hardest to sustain. The practice's change records are configuration change control operating, for the estate it covers.
What this does not claim: May partially address the requirement, and only for the OT estate — enterprise IT changes inside the CUI boundary need their own change process, and that is where most of a defense contractor's boundary usually sits. Defining which change types are configuration-controlled system-wide, and monitoring change activity beyond OT, remain separate work.
- Route OT changes through combined safety-and-security review with named approvers
- Capture emergency changes and review them after the fact
- Audit change records against observed reality on a cadence
- Completed OT change records with approvals and testing
- Emergency-change closure reviews
- Periodic change-record audits
Where this holds: Holds for OT within the assessed boundary; the enterprise side of the requirement is untouched by this practice.
Review status: Pending NIST SME review · Reviewed by Brilliant at the Basics editorial — practitioner-authored; NIST SME review pending · updated 2026-08-06