CCI-000323
CCI-000323 Definition
| Status | |
| Type | CheckType.policy |
Master Assessment Datasheet
Implementation Guidance
Determine if [CM-03(01)_ODP[01]; mechanisms used to automate configuration change control are defined] are used to notify [CM-03(01)_ODP[02]; approval authorities to be notified of and request approval for proposed changes to the system are defined] of proposed changes to the system and request change approval.
Validation Procedures
Examine: [SELECT FROM: Configuration management policy; procedures addressing system configuration change control; configuration management plan; system design documentation; system architecture and configuration documentation; automated configuration control mechanisms; system configuration settings and associated documentation; change control records; system audit records; change approval requests; change approvals; system security plan; other relevant documents or records]. Interview: [SELECT FROM: Organizational personnel with configuration change control responsibilities; organizational personnel with information security responsibilities; system/network administrators; system developers; members of change control board or similar]. Test: [SELECT FROM: Organizational processes for configuration change control; automated mechanisms implementing configuration change control activities].