This objective requires your organization to have the capability to detect and identify unauthorized changes to systems that store, process, or transmit Controlled Unclassified Information (CUI). This includes changes that were not approved or that deviate from your baseline configuration.