unified
UC-CONFIG-03 — Separate environments and protect production data in testing
Separate development, test, and production environments, and enforce physical and logical access restrictions so only authorized personnel can make changes to production systems. Select, protect, and manage information used for testing, anonymizing or masking production data before use in non-production environments and removing it when testing completes.
Record JSON · Open in map · Data retrieval guide
Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.
Attributes
- domain
- Secure Configuration & Change Management
- type
- preventive
- category
- technical
Details
- unified_id
- UC-CONFIG-03
- title
- Separate environments and protect production data in testing
- statement
- Separate development, test, and production environments, and enforce physical and logical access restrictions so only authorized personnel can make changes to production systems. Select, protect, and manage information used for testing, anonymizing or masking production data before use in non-production environments and removing it when testing completes.
- domain
- Secure Configuration & Change Management
- control_type
- preventive
- control_category
- technical
- members
- framework
- nist-800-53
- control_id
- CM-5
- coverage
- full
- relationship
- superset_of
- framework
- iso-27001
- control_id
- A.8.31
- coverage
- full
- relationship
- superset_of
- framework
- iso-27001
- control_id
- A.8.33
- coverage
- full
- relationship
- superset_of
- guidance
Source
No record-specific source URL is provided.
Connections
- SOX ITGC Testing tests UC-CONFIG-03 — Separate environments and protect production data in testing
- UC-CONFIG-03 — Separate environments and protect production data in testing maps_to CM-5 — Access Restrictions for Change
- framework
- nist-800-53
- control_id
- CM-5
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- Rev. 5
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- UC-CONFIG-03 — Separate environments and protect production data in testing maps_to A.8.33 — Test information
- framework
- iso-27001
- control_id
- A.8.33
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- 2022
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- ISO 27001 Stage 2 Annex A Controls Audit tests UC-CONFIG-03 — Separate environments and protect production data in testing
- Security Control Assessment & POA&M Remediation tests UC-CONFIG-03 — Separate environments and protect production data in testing
- UC-CONFIG-03 — Separate environments and protect production data in testing mitigates Poor configuration management and insecure baseline drift
- strength
- related
- rationale
- Restricting who can alter production and separating environments reduces ad-hoc unauthorized production changes that cause drift.
- Change & Release Management (CAB) operates UC-CONFIG-03 — Separate environments and protect production data in testing
- UC-CONFIG-03 — Separate environments and protect production data in testing maps_to A.8.31 — Separation of development, test and production environments
- framework
- iso-27001
- control_id
- A.8.31
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- 2022
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- UC-CONFIG-03 — Separate environments and protect production data in testing mitigates Absent or weak change-control procedures
- strength
- related
- rationale
- Separating environments and restricting production changes to authorized personnel supports change control, but the request-test-approve process (UC-CONFIG-02) is the operative defense against unapproved or untested changes.