CCI-000324
CCI-000324 Definition
| Status | |
| Type | CheckType.policy |
Master Assessment Datasheet
Implementation Guidance
Determine if [CM-03(01)_ODP[01]; mechanisms used to automate configuration change control are defined] are used to highlight proposed changes to the system that have not been approved or disapproved within [CM-03(01)_ODP[03]l the time period after which to highlight changes that have not been approved or disapproved is defined].
Validation Procedures
Examine: [SELECT FROM: Configuration management policy; procedures addressing system configuration change control; configuration management plan; system design documentation; system architecture and configuration documentation; automated configuration control mechanisms; system configuration settings and associated documentation; change control records; system audit records; change approval requests; change approvals; system security plan; other relevant documents or records]. Interview: [SELECT FROM: Organizational personnel with configuration change control responsibilities; organizational personnel with information security responsibilities; system/network administrators; system developers; members of change control board or similar]. Test: [SELECT FROM: Organizational processes for configuration change control; automated mechanisms implementing configuration change control activities].