STIGhub
STIGs
RMF Controls
Compare
← All Controls
CM-1
Configuration Management
Rev 5
Policy and Procedures
CCI Identifiers (26)
CCI-000286
Defines the frequency with which to review and update the configuration management policies.
CCI-000287
Develop and document an organization-level; mission/business process-level; and/or system-level configuration management policy that addresses purpose, scope, roles, responsibilities, management commitment, coordination among organizational entities, and compliance.
CCI-000288
The organization disseminates formal, documented configuration management policy to elements within the organization having associated configuration management roles and responsibilities.
CCI-000289
Review and update, on an organization-defined frequency, the configuration management policy.
CCI-000290
Develop and document procedures to facilitate the implementation of the organization-level; mission/business process-level; and/or system-level configuration management policy and the associated configuration management controls.
CCI-000291
The organization disseminates formal, documented procedures to facilitate the implementation of the configuration management policy and associated configuration management controls.
CCI-000292
Review and update, on an organization-defined frequency, the procedures to facilitate the implementation of the organization-level; mission/business process-level; and/or system-level configuration management policy and associated configuration management controls.
CCI-001584
Defines the frequency with which to review and update configuration management procedures.
CCI-001820
The organization documents a configuration management policy that addresses purpose, scope, roles, responsibilities, management commitment, coordination among organizational entities, and compliance.
deprecated
CCI-001821
Defines the organizational personnel or roles to whom the organization-level; mission/business process-level; and/or system-level configuration management policy is to be disseminated.
CCI-001822
Disseminate the organization-level; mission/business process-level; and/or system-level configuration management policy to organization-defined personnel or roles.
CCI-001823
The organization documents the procedures to facilitate the implementation of the configuration management policy and associated configuration management controls.
deprecated
CCI-001824
Defines the organizational personnel or roles to whom the organization-level; mission/business process-level; and/or system-level configuration management procedures are to be disseminated.
CCI-001825
Disseminate to organization-defined personnel or roles the procedures to facilitate the implementation of the organization-level; mission/business process-level; and/or system-level configuration management policy and associated configuration management controls.
CCI-003897
Develop and document an organization-level; mission/business process-level; and/or system-level configuration management policy that is consistent with applicable laws, Executive Orders, directives, regulations, policies, standards, and guidelines.
CCI-003898
Defines the official to manage the development, documentation, and dissemination of the configuration management policy.
CCI-003899
Designate an organization-defined official to manage the development and documentation of the configuration management policy.
CCI-003900
Designate an organization-defined official to manage the dissemination of the configuration management policy.
CCI-003901
Defines the official to manage the development, documentation, and dissemination of the configuration management procedures.
CCI-003902
Designate an organization-defined official to manage the development and documentation of the configuration management procedures.
CCI-003903
Designate an organization-defined official to manage the dissemination of the configuration management procedures.
CCI-003904
Review and update the configuration management policy following organization-defined events.
CCI-003905
Defines the events for when the policy will be reviewed and updated.
CCI-003906
Review and update, on an organization-defined frequency, the current configuration management procedures.
CCI-003907
Review and update the configuration management procedures following organization-defined events.
CCI-003908
Defines the events for when the procedures will be reviewed and updated.
Linked STIG Checks (1)
Across 1 STIGs. Click to expand.
▶
Cisco ASA Firewall Security Technical Implementation Guide
1 check