This objective requires your organization to identify and document who is authorized to make configuration changes to systems that store, process, or transmit Controlled Unclassified Information (CUI). This includes both individuals and roles with administrative, security, or change management privileges.