This control requires your organization to analyze and document the security impact of any proposed configuration changes before those changes are implemented—especially when those changes affect systems that store, process, or transmit Controlled Unclassified Information (CUI).