unified

UC-CONFIG-02 — Authorize, test, and approve changes before production

Manage changes to applications, databases, infrastructure, configurations, and procedures through a documented process in which changes are requested, analyzed for security and risk impact, authorized, tested, approved, and implemented by appropriate personnel. Require migration to production to be performed by individuals independent of development, and retain records evidencing each step. Define rollback plans and an emergency-change path with retrospective review and approval.

Record JSON · Open in map · Data retrieval guide

Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.

Attributes

domain
Secure Configuration & Change Management
type
preventive
category
administrative

Details

unified_id
UC-CONFIG-02
title
Authorize, test, and approve changes before production
statement
Manage changes to applications, databases, infrastructure, configurations, and procedures through a documented process in which changes are requested, analyzed for security and risk impact, authorized, tested, approved, and implemented by appropriate personnel. Require migration to production to be performed by individuals independent of development, and retain records evidencing each step. Define rollback plans and an emergency-change path with retrospective review and approval.
domain
Secure Configuration & Change Management
control_type
preventive
control_category
administrative
members
  • framework
    nist-800-53
    control_id
    CM-3
    coverage
    full
    relationship
    superset_of
  • framework
    nist-800-53
    control_id
    CM-4
    coverage
    full
    relationship
    superset_of
  • framework
    iso-27001
    control_id
    A.8.32
    coverage
    full
    relationship
    superset_of
  • framework
    soc2
    control_id
    CC8.1
    coverage
    full
    relationship
    superset_of
  • framework
    sox
    control_id
    ITGC-CM
    coverage
    full
    relationship
    superset_of
guidance

    Source

    No record-specific source URL is provided.

    Connections