CCI-000295
CCI-000295 Definition
Status | |
Type | CheckType.policy |
Master Assessment Datasheet
Implementation Guidance
The organization being inspected/assessed maintains a current baseline configuration of the information system.
Validation Procedures
The organization conducting the inspection/assessment obtains and examines the current baseline to ensure the current configuration matches the current documented baseline. Supplemental Guidance: This control establishes baseline configurations for information systems and system components including communications and connectivity-related aspects of systems. Baseline configurations are documented, formally reviewed and agreed-upon sets of specifications for information systems or configuration items within those systems. Baseline configurations serve as a basis for future builds, releases, and/or changes to information systems. Baseline configurations include information about information system components (e.g., standard software packages installed on workstations, notebook computers, servers, network components, or mobile devices; current version numbers and patch information on operating systems and applications; and configuration settings/parameters), network topology, and the logical placement of those components within the system architecture. Maintaining baseline configurations requires creating new baselines as organizational information systems change over time. Baseline configurations of information systems reflect the current enterprise architecture. Related to: CM-3, CM-6, CM-8, CM-9, SA-10, PM-5, PM-7
Compelling Evidence
1.) Baseline configuration of the information system (hardware and software list)