STIGhub
STIGs
RMF Controls
Compare
← All Controls
SA-10
System and Services Acquisition
Rev 3
Developer Configuration Management
CCI Identifiers (33)
CCI-000692
Require the developer of the system, system component, or system service to implement only organization-approved changes to the system, component, or service.
CCI-000682
The organization requires information system developers to perform configuration management during information system design.
CCI-000683
The organization requires information system developers to perform configuration management during information system development.
CCI-000684
The organization requires information system developers to perform configuration management during information system implementation.
CCI-000685
The organization requires information system developers to perform configuration management during information system operation.
CCI-000686
The organization requires information system integrators to perform configuration management during information system design.
CCI-000687
The organization requires information system integrators to perform configuration management during information system development.
CCI-000688
The organization requires information system integrators to perform configuration management during information system implementation.
CCI-000689
The organization requires information system integrators to perform configuration management during information system operation.
CCI-000690
The organization requires information system developers to manage and control changes to the information system during design.
CCI-000691
The organization requires information system integrators to manage and control changes to the information system during design.
CCI-000693
The organization requires information system integrators to implement only organization-approved changes.
CCI-000694
Require the developer of the system, system component, or system service to document approved changes to the system, component, or service.
CCI-000695
The organization requires information system integrators to document approved changes to the information system.
CCI-000696
The organization requires that information system developers track security flaws and flaw resolution.
CCI-000697
The organization requires information system integrators to track security flaws and flaw resolution.
CCI-001650
The organization requires the information system developers to manage and control changes to the information system during development.
CCI-001651
The organization requires the information system integrators to manage and control changes to the information system during development.
CCI-001652
The organization requires the information system developers to manage and control changes to the information system during implementation.
CCI-001653
The organization requires the information system integrators to manage and control changes to the information system during implementation.
CCI-001654
The organization requires the information system developers to manage and control changes to the information system during modification.
CCI-001655
The organization requires the information system integrators to manage and control changes to the information system during modification.
CCI-003155
Require the developer of the system, system component, or system service to perform configuration management during system, component, or service design, development, implementation, operation and/or disposal.
CCI-003156
Require the developer of the system, system component, or system service to document the integrity of changes to organization-defined configuration items under configuration management.
CCI-003157
Require the developer of the system, system component, or system service to manage the integrity of changes to organization-defined configuration items under configuration management.
CCI-003158
Require the developer of the system, system component, or system service to control the integrity of changes to organization-defined configuration items under configuration management.
CCI-003159
Defines the configuration items under configuration management that require the integrity of changes to be documented, managed and controlled.
CCI-003160
Require the developer of the system, system component, or system service to document the potential security impacts of approved changes to the system, component, or service.
CCI-003161
Require the developer of the system, system component, or system service to track security flaws within the system, component, or service.
CCI-003162
Require the developer of the system, system component, or system service to track flaw resolution within the system, component, or service.
CCI-003163
Require the developer of the system, system component, or system service to report findings of security flaws and flaw resolution within the system, component, or service to organization-defined personnel.
CCI-003164
Defines the personnel to whom security flaw findings and flaw resolution within the system, component, or service are reported.
CCI-004794
Require the developer of the system, system component, or system service to document the potential privacy impacts of approved changes to the system, component, or service.
Linked STIG Checks (1)
Across 1 STIGs. Click to expand.
▶
Application Security and Development Security Technical Implementation Guide
1 check