STIGhub
STIGs
RMF Controls
Compare
← All Controls
CM-3
Configuration Management
Rev 5
Configuration Change Control
CCI Identifiers (15)
CCI-000313
Determine and document the types of changes to the system that are configuration-controlled.
CCI-000314
Approve or disapprove configuration-controlled changes to the system, with explicit consideration for security impact analyses.
CCI-000315
The organization documents approved configuration-controlled changes to the system.
CCI-000316
Retain records of configuration-controlled changes to the system for an organization-defined time period.
CCI-000317
The organization reviews records of configuration-controlled changes to the system.
CCI-000318
Monitor and review activities associated with configuration-controlled changes to the system.
CCI-000319
Coordinate and provides oversight for configuration change control activities through an organization-defined configuration change control element that convenes at the organization-defined frequency, and/or for any organization-defined configuration change conditions.
CCI-000320
Defines the frequency with which to convene the configuration change control element.
CCI-000321
Defines configuration change conditions that prompt the configuration change control element to convene.
CCI-001586
Defines the configuration change control element responsible for coordinating and providing oversight for configuration change control activities.
CCI-001740
Review proposed configuration-controlled changes to the system.
CCI-001741
Document configuration change decisions associated with the system.
CCI-001819
Implement approved configuration-controlled changes to the system.
CCI-002056
Defines the time period the records of configuration-controlled changes are to be retained.
CCI-003912
Approve or disapprove configuration-controlled changes to the system, with explicit consideration for privacy impact analyses.
Linked STIG Checks (13)
Across 5 STIGs. Click to expand.
▶
Red Hat Enterprise Linux 7 Security Technical Implementation Guide
7 checks
▶
SUSE Linux Enterprise Server v11 for System z Security Technical Implementation Guide
3 checks
▶
z/OS Front End Processor for ACF2 Security Technical Implementation Guide
1 check
▶
z/OS Front End Processor for RACF Security Technical Implementation Guide
1 check
▶
zOS Front End Processor for TSS Security Technical Implementation Guide
1 check