Control Packs · CHG-003 · v1.0.0

Runtime Configuration and Feature Switches

Name the switches that change what production does, say who may change each one and what it currently controls, and keep a record of every change and the way back.

Status: review · Review: not independent. This is design guidance; review status does not establish independent verification or compliance.

What this safeguard addresses

Identify the switches whose change is consequential, state who may change each and what it currently controls, record every change with the person and the previous value, and keep a stated way back.

  • Production behaviour changes without going through a deploymentA flag, environment value or remote setting changes what the system does, bypassing the approval, rollout, health check and rollback that a deployment would have carried, and often with no record of who changed it.
Versioned applicability rule
{
  "any": [
    {
      "characteristic": "PRODUCTION_MODIFICATION",
      "equals": true
    },
    {
      "characteristic": "CONSEQUENTIAL_ACTION",
      "equals": true
    }
  ]
}

Decisions for the project owner

Leave a decision open when its value is unknown. Suggested values become confirmed only through an explicit user decision.

  • Which settings change what the system does in production without a deployment?A switch nobody has listed is a switch nobody reviews. The service cannot tell from a feature description which values are merely tuning and which turn behaviour on and off.CHG-003-Q1 · scope
  • Who may change a consequential switch, and what happens at the moment it changes?Changing a switch is usually far easier than shipping code, which is exactly why it needs its own answer rather than inheriting the deployment process by assumption.CHG-003-Q2 · choice

Requirements for the coding agent

  • CHG-003-R1Record the switches whose change alters production behaviour, and for each one state what it currently controls, so a switch cannot be flipped on an understanding of it that is out of date.
  • CHG-003-R2Enforce the confirmed authority for changing a consequential switch, and record each change with the acting person, the previous value, the new value and the time, without recording secrets.

Tests and evidence to retain

  • SWITCH_INVENTORY_TESTCompare the switches the running system reads against the recorded list and fail on one that is not described.
  • SWITCH_AUTHORITY_TESTAttempt a switch change as an actor outside the confirmed authority and verify it is refused and recorded.
  • SWITCH_REVERSAL_TESTChange a consequential switch, verify the change is recorded with its previous value, then restore that value and verify the system returns to the prior behaviour.
  • configuration_or_policy
  • implementation_location
  • test_result
  • operational_procedure

Passing a published example shows that example's behavior. A coding agent's implementation report remains a claim until its evidence is independently checked.

Related guidance

  • CM-3 · Configuration Change ControlNIST_SP_800_53_5_2_0 · partially addressesListing consequential switches, confirming who may change them, and recording each change address change control for runtime settings only. They do not cover the wider configuration management baseline.
  • CM-5 · Access Restrictions for ChangeNIST_SP_800_53_5_2_0 · partially addressesEnforcing a confirmed authority at the point a switch changes addresses access restriction for that path; it does not cover restrictions across the whole change environment.
  • AU-2 · Event LoggingNIST_SP_800_53_5_2_0 · partially addressesRecording the actor, previous value and new value covers this event class only, and does not establish an organization-wide logging policy.

Mappings indicate contextual relevance or partial support. They do not establish equivalence, certification, government endorsement, or complete framework implementation.

Continue your review