Control Packs · OBS-002 · v1.0.0
Administrative Change Visibility
Make privileged production changes attributable, reviewable, and distinguishable from automated routine activity.
Status: review · Review: not independent. This is design guidance; review status does not establish independent verification or compliance.
What this safeguard addresses
Record privacy-minimized evidence for privileged production changes, approvals, outcomes, and recovery actions.
- Privileged production change cannot be reconstructedAn administrative change lacks an attributable actor, approval, scope, outcome, or correlation with the deployment and recovery record.
Versioned applicability rule
{
"all": [
{
"characteristic": "PRIVILEGED_ACTION",
"equals": true
},
{
"characteristic": "PRODUCTION_MODIFICATION",
"equals": true
}
]
}Decisions for the project owner
Leave a decision open when its value is unknown. Suggested values become confirmed only through an explicit user decision.
- Which administrative events must be available for reconstruction and review?Auditability must support a defined review purpose without silently creating a broad retention policy.OBS-002-Q1 · multi_select
Requirements for the coding agent
- OBS-002-R1Emit privacy-minimized events for privileged production changes with actor, approval, scope, outcome, and recovery correlation.
Tests and evidence to retain
- ADMIN_AUDIT_TRAIL_TESTVerify approved, denied, emergency, failed, rolled-back, and automated administrative changes are distinguishable.
- implementation_location
- test_result
- telemetry_definition
- operational_procedure
Passing a published example shows that example's behavior. A coding agent's implementation report remains a claim until its evidence is independently checked.
Related guidance
- AU-2 · Event LoggingNIST_SP_800_53_5_2_0 · partially addressesAdministrative change events provide focused logging for reconstruction; they do not establish a complete logging program.
- AU-3 · Content of Audit RecordsNIST_SP_800_53_5_2_0 · partially addressesActor, approval, scope, outcome, and recovery correlation define focused audit content; they do not cover every record.
- CM-3 · Configuration Change ControlNIST_SP_800_53_5_2_0 · partially addressesAdministrative change visibility supports controlled change review; it does not establish complete configuration governance.
Mappings indicate contextual relevance or partial support. They do not establish equivalence, certification, government endorsement, or complete framework implementation.
- National Institute of Standards and Technology — Security and Privacy Controls for Information Systems and OrganizationsGUIDANCE_AUDITABILITY
- National Institute of Standards and Technology — Security and Privacy Controls for Information Systems and OrganizationsGUIDANCE_LEAST_AUTHORITY
- National Institute of Standards and Technology — Security and Privacy Controls for Information Systems and OrganizationsGUIDANCE_NIST_SP_800_53_5_2_0