unified
UC-SDLC-06 — Maintain configuration control over systems and code
Maintain configuration management over solution components throughout development and operation: identify configuration items, establish and protect baselines for code, dependencies, and build settings, record and verify configuration information, and review deviations. Require developers to track the integrity of changes to configuration items, implement only approved changes, and track and resolve resulting security flaws.
Record JSON · Open in map · Data retrieval guide
Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.
Attributes
- domain
- Secure Development (SDLC) & Application Security
- type
- preventive
- category
- administrative
Details
- unified_id
- UC-SDLC-06
- title
- Maintain configuration control over systems and code
- statement
- Maintain configuration management over solution components throughout development and operation: identify configuration items, establish and protect baselines for code, dependencies, and build settings, record and verify configuration information, and review deviations. Require developers to track the integrity of changes to configuration items, implement only approved changes, and track and resolve resulting security flaws.
- domain
- Secure Development (SDLC) & Application Security
- control_type
- preventive
- control_category
- administrative
- members
- framework
- nist-800-53
- control_id
- SA-10
- coverage
- full
- relationship
- superset_of
- framework
- cobit-2019
- control_id
- BAI10
- coverage
- full
- relationship
- superset_of
- guidance
Source
No record-specific source URL is provided.
Connections
- SOX ITGC Testing tests UC-SDLC-06 — Maintain configuration control over systems and code
- UC-SDLC-06 — Maintain configuration control over systems and code maps_to SA-10 — Developer Configuration Management
- framework
- nist-800-53
- control_id
- SA-10
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- Rev. 5
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- UC-SDLC-06 — Maintain configuration control over systems and code maps_to BAI10 — Managed Configuration
- framework
- cobit-2019
- control_id
- BAI10
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- 2019
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- UC-SDLC-06 — Maintain configuration control over systems and code mitigates Loss of system maintainability
- strength
- primary
- rationale
- Versioned, protected baselines for code, dependencies and build settings cure the unversioned-software cause of lost maintainability.
- UC-SDLC-06 — Maintain configuration control over systems and code mitigates Software and information-system failure
- strength
- related
- rationale
- Allowing only approved, integrity-tracked changes reduces failed releases and configuration-induced failures.
- UC-SDLC-06 — Maintain configuration control over systems and code mitigates Malicious supply-chain injection of tampered hardware/software
- strength
- related
- rationale
- Protected dependency baselines and configuration-integrity verification help detect tampered or counterfeit components.
- UC-SDLC-06 — Maintain configuration control over systems and code mitigates Absent or weak change-control procedures
- strength
- primary
- rationale
- Implementing only approved changes and tracking the integrity of changes to configuration items directly prevent unauthorized/untested changes.
- UC-SDLC-06 — Maintain configuration control over systems and code mitigates Vulnerabilities introduced during software development
- strength
- related
- rationale
- Tracking and resolving security flaws in configuration items reduces residual exploitable defects.
- Change & Release Management (CAB) operates UC-SDLC-06 — Maintain configuration control over systems and code
- UC-SDLC-06 — Maintain configuration control over systems and code mitigates AI supply-chain compromise and provider concentration
- strength
- related
- rationale
- Baseline control and integrity verification of dependencies help detect malicious/backdoored third-party libraries.
- UC-SDLC-06 — Maintain configuration control over systems and code mitigates Malware delivery, insertion and compromise of systems
- strength
- related
- rationale
- Tracking integrity of changes to configuration items surfaces unauthorized/malicious modification of system software.