CCI-000368
CCI-000368 Definition
| Status | |
| Type | CheckType.policy |
Master Assessment Datasheet
Implementation Guidance
Determine if: - any deviations from established configuration settings for [CM-06_ODP[02]; system components for which approval of deviations is needed are defined] are identified and documented based on [CM-06_ODP[03]; operational requirements necessitating approval of deviations are defined]. - any deviations from established configuration settings for [CM-06_ODP[02]; system components for which approval of deviations is needed are defined] are approved.
Validation Procedures
Examine: [SELECT FROM: Configuration management policy; procedures addressing configuration settings for the system; configuration management plan; system design documentation; system configuration settings and associated documentation; common secure configuration checklists; system component inventory; evidence supporting approved deviations from established configuration settings; change control records; system data processing and retention permissions; system audit records; system security plan; privacy plan; other relevant documents or records]. Interview: [SELECT FROM: Organizational personnel with security configuration management responsibilities; organizational personnel with privacy configuration management responsibilities; organizational personnel with information security and privacy responsibilities; system/network administrators]. Test: [SELECT FROM: Organizational processes for managing configuration settings; mechanisms that implement, monitor, and/or control system configuration settings; mechanisms that identify and/or document deviations from established configuration settings].