Cyber Posture

NIST 800-53 r5 · Controls catalogue · Family CM

CM-4Impact Analyses

Analyze changes to the system to determine potential security and privacy impacts prior to change implementation.

Last updated: 09 May 2026 03:25 UTC

Implementations targeting this control (0)

ATT&CK techniques this control mitigates (0)

Weaknesses this control addresses (6)AI

CWEs ranked by how often they appear in real CVEs. The rationale describes how this control reduces exploitability of each weakness class.

CWE Name CVEs Why this control addresses it
CWE-284Improper Access Control4,832Prior analysis ensures modifications do not create or worsen improper access control enforcement.
CWE-269Improper Privilege Management2,907Reviewing changes for security impacts prevents introduction of improper privilege assignments or escalations.
CWE-732Incorrect Permission Assignment for Critical Resource1,824Changes to permissions on critical resources are assessed to prevent incorrect assignments.
CWE-285Improper Authorization1,230Evaluating change impacts helps avoid deployment of incorrect or missing authorization logic.
CWE-693Protection Mechanism Failure476Impact analysis identifies changes that could weaken or disable existing protection mechanisms.
CWE-15External Control of System or Configuration Setting59Impact analysis of configuration changes reduces the risk of deploying settings that permit unauthorized external control.

Top CVEs where this control is the strongest mitigation

CVE Risk CVSS EPSS Match
No CVEs annotated to this control yet — the per-CVE backfill is in progress.

Other controls in family CM

CM-1 CM-10 CM-11 CM-12 CM-13 CM-14 CM-2 CM-3 CM-5 CM-6 CM-7 CM-8 CM-9