CM-3—Configuration Change Control
>Control Description
Determine and document the types of changes to the system that are configuration-controlled;
Review proposed configuration-controlled changes to the system and approve or disapprove such changes with explicit consideration for security and privacy impact analyses;
Document configuration change decisions associated with the system;
Implement approved configuration-controlled changes to the system;
Retain records of configuration-controlled changes to the system for ⚙organization-defined time period;
Monitor and review activities associated with configuration-controlled changes to the system; and
Coordinate and provide oversight for configuration change control activities through ⚙organization-defined configuration change control element that convenes [Selection (one or more): ⚙organization-defined frequency; when ⚙organization-defined configuration change conditions].
>Related Controls
Ask AI
Configure your API key to use AI features.