This objective ensures your systems are configured to enforce change control restrictions, meaning that only authorized and approved changes can be made—and that all changes are traceable on systems that handle Controlled Unclassified Information (CUI).