{"catalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","kind":"record","record":{"attributes":{"category":"technical","domain":"Secure Configuration & Change Management","type":"preventive"},"canonicalUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-CONFIG-03","description":"Separate development, test, and production environments, and enforce physical and logical access restrictions so only authorized personnel can make changes to production systems. Select, protect, and manage information used for testing, anonymizing or masking production data before use in non-production environments and removing it when testing completes.","details":{"control_category":"technical","control_type":"preventive","domain":"Secure Configuration & Change Management","guidance":[],"members":[{"control_id":"CM-5","coverage":"full","framework":"nist-800-53","relationship":"superset_of"},{"control_id":"A.8.31","coverage":"full","framework":"iso-27001","relationship":"superset_of"},{"control_id":"A.8.33","coverage":"full","framework":"iso-27001","relationship":"superset_of"}],"statement":"Separate development, test, and production environments, and enforce physical and logical access restrictions so only authorized personnel can make changes to production systems. Select, protect, and manage information used for testing, anonymizing or masking production data before use in non-production environments and removing it when testing completes.","title":"Separate environments and protect production data in testing","unified_id":"UC-CONFIG-03"},"id":"uc:UC-CONFIG-03","mapUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-CONFIG-03","sourceIds":["iso-27001","nist-800-53"],"sourceUrl":null,"title":"UC-CONFIG-03 — Separate environments and protect production data in testing","type":"unified"},"relationships":[{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:0fbdffb79e264e3c215481a02c618b0442126bf5a3fcb0876224454abf22821f","properties":{},"sourceDetailPath":"/data/v1/records/wf-s5-a655abf2.json","sourceId":"wf:S5","targetDetailPath":"/data/v1/records/uc-uc-config-03-3a08a2b1.json","targetId":"uc:UC-CONFIG-03","type":"tests"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:2eafb7040b06c8cfbda5677c9863e4ec1cd91c16c43dc3075b96e0bcdd9c1b99","properties":{"control_id":"CM-5","coverage":"full","delta":null,"framework":"nist-800-53","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"Rev. 5"},"sourceDetailPath":"/data/v1/records/uc-uc-config-03-3a08a2b1.json","sourceId":"uc:UC-CONFIG-03","targetDetailPath":"/data/v1/records/ctrl-nist-800-53-cm-5-2aede1f4.json","targetId":"ctrl:nist-800-53:CM-5","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:65364c502c601d992737a86ccb5ece989090bb03969c8d4658bd9fa45839eade","properties":{"control_id":"A.8.33","coverage":"full","delta":null,"framework":"iso-27001","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2022"},"sourceDetailPath":"/data/v1/records/uc-uc-config-03-3a08a2b1.json","sourceId":"uc:UC-CONFIG-03","targetDetailPath":"/data/v1/records/ctrl-iso-27001-a-8-33-cabca252.json","targetId":"ctrl:iso-27001:A.8.33","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:8a1b8b74fe45f0fc2922966dd06ef857a9eb83dfd448d1dd95f403c351325de4","properties":{},"sourceDetailPath":"/data/v1/records/wf-d06-c9616fb8.json","sourceId":"wf:D06","targetDetailPath":"/data/v1/records/uc-uc-config-03-3a08a2b1.json","targetId":"uc:UC-CONFIG-03","type":"tests"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:8afb8e7c8142645503ee2fb176df5258752bf594a98a99c9913946dbd83fcc21","properties":{},"sourceDetailPath":"/data/v1/records/wf-c9-75fb1752.json","sourceId":"wf:C9","targetDetailPath":"/data/v1/records/uc-uc-config-03-3a08a2b1.json","targetId":"uc:UC-CONFIG-03","type":"tests"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:a147b69e4978a218885cf9aae5692339be7b34b9176dd725e6ff7b3d90e7b7e2","properties":{"rationale":"Restricting who can alter production and separating environments reduces ad-hoc unauthorized production changes that cause drift.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-config-03-3a08a2b1.json","sourceId":"uc:UC-CONFIG-03","targetDetailPath":"/data/v1/records/risk-config-poor-baseline-drift-2dd66324.json","targetId":"risk:config-poor-baseline-drift","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:b022fc233777d25d28095b221559ac0d3cf7e839c8481f82e0d806e22d4686ea","properties":{},"sourceDetailPath":"/data/v1/records/wf-c41-f5b6a3b6.json","sourceId":"wf:C41","targetDetailPath":"/data/v1/records/uc-uc-config-03-3a08a2b1.json","targetId":"uc:UC-CONFIG-03","type":"operates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:c167e1277136936a9d4545736150b97fc15aa63218aa40c5de8daffcfc664e3b","properties":{"control_id":"A.8.31","coverage":"full","delta":null,"framework":"iso-27001","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2022"},"sourceDetailPath":"/data/v1/records/uc-uc-config-03-3a08a2b1.json","sourceId":"uc:UC-CONFIG-03","targetDetailPath":"/data/v1/records/ctrl-iso-27001-a-8-31-eabf2a51.json","targetId":"ctrl:iso-27001:A.8.31","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:f95300720d3c8042c1a4f340525a57dee8e4fbed53eda5feaac4309fc4344d64","properties":{"rationale":"Separating environments and restricting production changes to authorized personnel supports change control, but the request-test-approve process (UC-CONFIG-02) is the operative defense against unapproved or untested changes.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-config-03-3a08a2b1.json","sourceId":"uc:UC-CONFIG-03","targetDetailPath":"/data/v1/records/risk-config-weak-change-control-e7d90eaf.json","targetId":"risk:config-weak-change-control","type":"mitigates"}],"schemaVersion":1}
