CCI-000289
CCI-000289 Definition
The organization reviews and updates, on an organization-defined frequency, the configuration management policy.
Status | |
Type | CheckType.policy |
Master Assessment Datasheet
Implementation Guidance
The organization being inspected/assessed reviews and updates, annually, the configuration management policy. The organization must document each occurrence of the reviews and update actions as an audit trail. DoD has defined the frequency as annually.
Validation Procedures
The organization conducting the inspection/assessment obtains and examines documentation of occurrence of reviews and update actions for the configuration management policy to ensure annual review and necessary updates are occurring. DoD has defined the frequency as annually.
Compelling Evidence
1.) Signed and dated configuration management policies with change log referenced