unified
UC-CONFIG-02 — Authorize, test, and approve changes before production
Manage changes to applications, databases, infrastructure, configurations, and procedures through a documented process in which changes are requested, analyzed for security and risk impact, authorized, tested, approved, and implemented by appropriate personnel. Require migration to production to be performed by individuals independent of development, and retain records evidencing each step. Define rollback plans and an emergency-change path with retrospective review and approval.
Record JSON · Open in map · Data retrieval guide
Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.
Attributes
- domain
- Secure Configuration & Change Management
- type
- preventive
- category
- administrative
Details
- unified_id
- UC-CONFIG-02
- title
- Authorize, test, and approve changes before production
- statement
- Manage changes to applications, databases, infrastructure, configurations, and procedures through a documented process in which changes are requested, analyzed for security and risk impact, authorized, tested, approved, and implemented by appropriate personnel. Require migration to production to be performed by individuals independent of development, and retain records evidencing each step. Define rollback plans and an emergency-change path with retrospective review and approval.
- domain
- Secure Configuration & Change Management
- control_type
- preventive
- control_category
- administrative
- members
- framework
- nist-800-53
- control_id
- CM-3
- coverage
- full
- relationship
- superset_of
- framework
- nist-800-53
- control_id
- CM-4
- coverage
- full
- relationship
- superset_of
- framework
- iso-27001
- control_id
- A.8.32
- coverage
- full
- relationship
- superset_of
- framework
- soc2
- control_id
- CC8.1
- coverage
- full
- relationship
- superset_of
- framework
- sox
- control_id
- ITGC-CM
- coverage
- full
- relationship
- superset_of
- guidance
Source
No record-specific source URL is provided.
Connections
- SOC 2 Type II Interim Testing tests UC-CONFIG-02 — Authorize, test, and approve changes before production
- SOX ITGC Testing tests UC-CONFIG-02 — Authorize, test, and approve changes before production
- UC-CONFIG-02 — Authorize, test, and approve changes before production maps_to CM-3 — Configuration Change Control
- framework
- nist-800-53
- control_id
- CM-3
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- Rev. 5
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- Change & Release Management (CAB) operates UC-CONFIG-02 — Authorize, test, and approve changes before production
- UC-CONFIG-02 — Authorize, test, and approve changes before production mitigates Poor configuration management and insecure baseline drift
- strength
- related
- rationale
- Gating changes through authorization and impact analysis prevents unauthorized changes that cause drift, though baseline monitoring is the operative control.
- ISO 27001 Stage 1 ISMS Documentation Review tests UC-CONFIG-02 — Authorize, test, and approve changes before production
- UC-CONFIG-02 — Authorize, test, and approve changes before production mitigates Inadequate vulnerability scanning and pre-release testing
- strength
- primary
- rationale
- Requiring test and approval before implementation directly mitigates releasing inadequately tested software.
- System ITGC Operation operates UC-CONFIG-02 — Authorize, test, and approve changes before production
- UC-CONFIG-02 — Authorize, test, and approve changes before production maps_to A.8.32 — Change management
- framework
- iso-27001
- control_id
- A.8.32
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- 2022
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- UC-CONFIG-02 — Authorize, test, and approve changes before production maps_to ITGC-CM — Program change management — changes to applications, databases, and infrastructure are requested, authorized, tested, approved, and migrated to production by appropriate personnel with segregation between development and production.
- framework
- sox
- control_id
- ITGC-CM
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- SOX §302/§404 (2002), PCAOB AS 2201
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- UC-CONFIG-02 — Authorize, test, and approve changes before production mitigates Emergent behaviour and unsafe AI system integration
- strength
- related
- rationale
- Security/risk impact analysis and pre-production testing catch integration interface/config errors, though emergent AI behaviour is not caught by change testing.
- UC-CONFIG-02 — Authorize, test, and approve changes before production mitigates Absent or weak change-control procedures
- strength
- primary
- rationale
- The documented request->impact-analysis->authorize->test->approve->independent-migration process is the change-control defense itself.
- SOC 2 Trust Services Readiness tests UC-CONFIG-02 — Authorize, test, and approve changes before production
- UC-CONFIG-02 — Authorize, test, and approve changes before production maps_to CM-4 — Impact Analyses
- framework
- nist-800-53
- control_id
- CM-4
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- Rev. 5
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- UC-CONFIG-02 — Authorize, test, and approve changes before production maps_to CC8.1 — The entity authorizes, designs, develops or acquires, configures, documents, tests, approves, and implements changes to infrastructure, data, software, and procedures to meet its objectives.
- framework
- soc2
- control_id
- CC8.1
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- 2017 TSC
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- ISO 27001 Stage 2 Annex A Controls Audit tests UC-CONFIG-02 — Authorize, test, and approve changes before production