unified
UC-CONFIG-09 — Document configuration management policy, plan, and procedures
Develop, document, and implement a configuration management plan defining roles, responsibilities, processes, and procedures for identifying, managing, and protecting configuration items throughout the system development life cycle. Deploy these expectations through approved policies and actionable procedures, review them periodically, and update them when the environment or organization changes.
Record JSON · Open in map · Data retrieval guide
Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.
Attributes
- domain
- Secure Configuration & Change Management
- type
- preventive
- category
- administrative
Details
- unified_id
- UC-CONFIG-09
- title
- Document configuration management policy, plan, and procedures
- statement
- Develop, document, and implement a configuration management plan defining roles, responsibilities, processes, and procedures for identifying, managing, and protecting configuration items throughout the system development life cycle. Deploy these expectations through approved policies and actionable procedures, review them periodically, and update them when the environment or organization changes.
- domain
- Secure Configuration & Change Management
- control_type
- preventive
- control_category
- administrative
- members
- framework
- nist-800-53
- control_id
- CM-9
- coverage
- full
- relationship
- superset_of
- framework
- coso-ic
- control_id
- P12
- coverage
- partial
- delta
- COSO expects policies and procedures deploying all control activities, not only CM
- relationship
- intersects_with
- guidance
Source
No record-specific source URL is provided.
Connections
- Secure Baseline & Integrity Drift Management operates UC-CONFIG-09 — Document configuration management policy, plan, and procedures
- UC-CONFIG-09 — Document configuration management policy, plan, and procedures mitigates Absent or weak change-control procedures
- strength
- related
- rationale
- Documenting configuration-management processes and roles enables disciplined change control, but executing change management is the operative defense.
- Security Control Assessment & POA&M Remediation tests UC-CONFIG-09 — Document configuration management policy, plan, and procedures
- UC-CONFIG-09 — Document configuration management policy, plan, and procedures mitigates Poor configuration management and insecure baseline drift
- strength
- related
- rationale
- A documented CM plan defining how configuration items are identified and managed is the foundation enabling baseline control, but not the operative drift defense.
- UC-CONFIG-09 — Document configuration management policy, plan, and procedures maps_to CM-9 — Configuration Management Plan
- framework
- nist-800-53
- control_id
- CM-9
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- Rev. 5
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- Policy Lifecycle Management oversees UC-CONFIG-09 — Document configuration management policy, plan, and procedures
- UC-CONFIG-09 — Document configuration management policy, plan, and procedures maps_to P12 — The organization deploys control activities through policies that establish what is expected and procedures that put policies into action.
- framework
- coso-ic
- control_id
- P12
- coverage
- partial
- delta
- COSO expects policies and procedures deploying all control activities, not only CM
- relationship
- intersects_with
- source_version
- 2013
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.