CMMC v2.0_CM.L2-3.4.3

CMMC v2.0

3.4 CONFIGURATION MANAGEMENT

CM.L2-3.4.3

Track review approve or disapprove and log changes to organizational systems.

Tracking reviewing approving/disapproving and logging changes is called configuration change control. Configuration change control for organizational systems involves the systematic proposal justification implementation testing review and disposition of changes to the systems including system upgrades and modifications. Configuration change control includes changes to baseline configurations for components and configuration items of systems changes to configuration settings for information technology products (e.g. operating systems applications firewalls routers and mobile devices) unscheduled and unauthorized changes and changes to remediate vulnerabilities.Processes for managing configuration changes to systems include Configuration Control Boards or Change Advisory Boards that review and approve proposed changes to systems. For new development systems or systems undergoing major upgrades organizations consider including representatives from development organizations on the Configuration Control Boards or Change Advisory Boards. Audit logs of changes include activities before and after changes are made to organizational systems and the activities required to implement such changes.[SP 800-128] provides guidance on configuration change control.

 

Click here to Start your FREE trial today!

Explainer video

 

What is a Cybersecurity Compliance Framework?

You don’t need to clutter your security and privacy programs with an ever-increasing number of tools as they become more sophisticated. The Lionfish platform offers a one-stop solution to track progress and monitor any framework, from custom-built ones to highly-specialized and in-demand top security and privacy frameworks and certifications.

With the Lionfish platform, every framework is supported with guided scoping, policies, controls, automated evidence collection, and continuous monitoring, ensuring efficient preparation for audits or attestation in minimal time.

The Lionfish platform is compatible with a wide range of security and privacy frameworks, including:

Click here to Start your FREE trial today!

Explainer video