{"catalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","kind":"record","record":{"attributes":{"category":"cyber_security","domain":["Secure Configuration & Change Management","Secure Development (SDLC) & Application Security"],"inherent_rating":"medium","taxonomy":["iso-27005-vulnerability"]},"canonicalUrl":"https://controlsmap.com/?v=1&node=risk%3Aconfig-weak-change-control","description":"Changes to systems, software, hardware, or configurations without formal approval and testing (including unauthorized or poorly tested hardware/config changes) introduce new vulnerabilities, instability, or failed releases.","details":{"category":"cyber_security","impact":"medium","inherent_rating":"medium","likelihood":"medium","risk_id":"config-weak-change-control","taxonomies":["iso-27005-vulnerability"],"treatment":"mitigate"},"id":"risk:config-weak-change-control","mapUrl":"https://controlsmap.com/?v=1&node=risk%3Aconfig-weak-change-control","sourceIds":["cobit-2019","coso-ic","iso-27001","nist-800-53","nist-csf-2","soc1","soc2","sox"],"sourceUrl":null,"title":"Absent or weak change-control procedures","type":"risk"},"relationships":[{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:01001ca64d4a07b32dc70644efba5e9d543b11d2731d0225ae79ebdb10d7a0c4","properties":{"rationale":"Authorizing, impact-assessing and acceptance-testing every change before implementation directly prevents unapproved/untested changes.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-sdlc-07-22470d8b.json","sourceId":"uc:UC-SDLC-07","targetDetailPath":"/data/v1/records/risk-config-weak-change-control-e7d90eaf.json","targetId":"risk:config-weak-change-control","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:6269d6c5ca06bc45a243eec12163d7a66ab5479a0ebf16d739b36841abc968b3","properties":{"rationale":"Implementing only approved changes and tracking the integrity of changes to configuration items directly prevent unauthorized/untested changes.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-sdlc-06-c1afc713.json","sourceId":"uc:UC-SDLC-06","targetDetailPath":"/data/v1/records/risk-config-weak-change-control-e7d90eaf.json","targetId":"risk:config-weak-change-control","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:8cffd54d2a669546e3e6de1f6dea63838956e2c961d1ad376bbdf876dd21ed07","properties":{"rationale":"Documenting configuration-management processes and roles enables disciplined change control, but executing change management is the operative defense.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-config-09-3da3afe2.json","sourceId":"uc:UC-CONFIG-09","targetDetailPath":"/data/v1/records/risk-config-weak-change-control-e7d90eaf.json","targetId":"risk:config-weak-change-control","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:bca9506a16c42dad9a6c1fe955d3c973f5c1b3ccd45b1901696f0d8da676c081","properties":{"rationale":"SDLC approval gates requiring significant changes be tested/approved before production contribute to change discipline, but the operative change controls are the dedicated UC-07 and UC-06 (approved-changes-only).","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-sdlc-01-b3583fd1.json","sourceId":"uc:UC-SDLC-01","targetDetailPath":"/data/v1/records/risk-config-weak-change-control-e7d90eaf.json","targetId":"risk:config-weak-change-control","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:be88249853f99703d19cefb0ad41a99cd93d410c5b64fd1ff7f47b7359d6cb3f","properties":{"rationale":"The authorize->test->approve->independent-migration gate IS the change-control process, directly preventing unapproved or untested changes.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-access-16-7a8d6d65.json","sourceId":"uc:UC-ACCESS-16","targetDetailPath":"/data/v1/records/risk-config-weak-change-control-e7d90eaf.json","targetId":"risk:config-weak-change-control","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:e79d9f1085a08b2c0078623a74f182c38115a275ebe83946bc0562b90d697b66","properties":{"rationale":"The documented request->impact-analysis->authorize->test->approve->independent-migration process is the change-control defense itself.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-config-02-175d55b0.json","sourceId":"uc:UC-CONFIG-02","targetDetailPath":"/data/v1/records/risk-config-weak-change-control-e7d90eaf.json","targetId":"risk:config-weak-change-control","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:f95300720d3c8042c1a4f340525a57dee8e4fbed53eda5feaac4309fc4344d64","properties":{"rationale":"Separating environments and restricting production changes to authorized personnel supports change control, but the request-test-approve process (UC-CONFIG-02) is the operative defense against unapproved or untested changes.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-config-03-3a08a2b1.json","sourceId":"uc:UC-CONFIG-03","targetDetailPath":"/data/v1/records/risk-config-weak-change-control-e7d90eaf.json","targetId":"risk:config-weak-change-control","type":"mitigates"}],"schemaVersion":1}
