{"catalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","kind":"record","record":{"attributes":{"category":"administrative","domain":"Secure Development (SDLC) & Application Security","type":"preventive"},"canonicalUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-SDLC-06","description":"Maintain configuration management over solution components throughout development and operation: identify configuration items, establish and protect baselines for code, dependencies, and build settings, record and verify configuration information, and review deviations. Require developers to track the integrity of changes to configuration items, implement only approved changes, and track and resolve resulting security flaws.","details":{"control_category":"administrative","control_type":"preventive","domain":"Secure Development (SDLC) & Application Security","guidance":[],"members":[{"control_id":"SA-10","coverage":"full","framework":"nist-800-53","relationship":"superset_of"},{"control_id":"BAI10","coverage":"full","framework":"cobit-2019","relationship":"superset_of"}],"statement":"Maintain configuration management over solution components throughout development and operation: identify configuration items, establish and protect baselines for code, dependencies, and build settings, record and verify configuration information, and review deviations. Require developers to track the integrity of changes to configuration items, implement only approved changes, and track and resolve resulting security flaws.","title":"Maintain configuration control over systems and code","unified_id":"UC-SDLC-06"},"id":"uc:UC-SDLC-06","mapUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-SDLC-06","sourceIds":["cobit-2019","nist-800-53"],"sourceUrl":null,"title":"UC-SDLC-06 — Maintain configuration control over systems and code","type":"unified"},"relationships":[{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:1b947dff5a7c9025905fade8e4a6022238d1e8c16d5b447bdad8525e498a7a44","properties":{},"sourceDetailPath":"/data/v1/records/wf-s5-a655abf2.json","sourceId":"wf:S5","targetDetailPath":"/data/v1/records/uc-uc-sdlc-06-c1afc713.json","targetId":"uc:UC-SDLC-06","type":"tests"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:2405006f8c7ad40f0de5531de22f7641b4aab85910a745e407ed32a40a35080f","properties":{"control_id":"SA-10","coverage":"full","delta":null,"framework":"nist-800-53","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"Rev. 5"},"sourceDetailPath":"/data/v1/records/uc-uc-sdlc-06-c1afc713.json","sourceId":"uc:UC-SDLC-06","targetDetailPath":"/data/v1/records/ctrl-nist-800-53-sa-10-12817dba.json","targetId":"ctrl:nist-800-53:SA-10","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:266413b704059cefdeb68ba76808b5444e25095d835aa595a43d1476260b7d3e","properties":{"control_id":"BAI10","coverage":"full","delta":null,"framework":"cobit-2019","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2019"},"sourceDetailPath":"/data/v1/records/uc-uc-sdlc-06-c1afc713.json","sourceId":"uc:UC-SDLC-06","targetDetailPath":"/data/v1/records/ctrl-cobit-2019-bai10-40479176.json","targetId":"ctrl:cobit-2019:BAI10","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:3c5f547348a371804de3bb0ec2e331d892292ebd788d74d525b76c585e5de1a9","properties":{"rationale":"Versioned, protected baselines for code, dependencies and build settings cure the unversioned-software cause of lost maintainability.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-sdlc-06-c1afc713.json","sourceId":"uc:UC-SDLC-06","targetDetailPath":"/data/v1/records/risk-tech-maintainability-breach-f075a363.json","targetId":"risk:tech-maintainability-breach","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:4b3eb5deef67095d7cae33c228548ceb31e70bb3887a30e5968ce7c3536d3230","properties":{"rationale":"Allowing only approved, integrity-tracked changes reduces failed releases and configuration-induced failures.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-sdlc-06-c1afc713.json","sourceId":"uc:UC-SDLC-06","targetDetailPath":"/data/v1/records/risk-tech-software-system-failure-2e2c5364.json","targetId":"risk:tech-software-system-failure","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:510361a83a227b7700820d4364fcf8eea9d9b142aa01b5d0753ec9e7c3981c4b","properties":{"rationale":"Protected dependency baselines and configuration-integrity verification help detect tampered or counterfeit components.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-sdlc-06-c1afc713.json","sourceId":"uc:UC-SDLC-06","targetDetailPath":"/data/v1/records/risk-tprm-supply-chain-injection-ad1f5937.json","targetId":"risk:tprm-supply-chain-injection","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:6269d6c5ca06bc45a243eec12163d7a66ab5479a0ebf16d739b36841abc968b3","properties":{"rationale":"Implementing only approved changes and tracking the integrity of changes to configuration items directly prevent unauthorized/untested changes.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-sdlc-06-c1afc713.json","sourceId":"uc:UC-SDLC-06","targetDetailPath":"/data/v1/records/risk-config-weak-change-control-e7d90eaf.json","targetId":"risk:config-weak-change-control","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:92ceb1d076a8a9fa8ba8d3f2dc000a4e82d92e74330279209def97be89639b2a","properties":{"rationale":"Tracking and resolving security flaws in configuration items reduces residual exploitable defects.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-sdlc-06-c1afc713.json","sourceId":"uc:UC-SDLC-06","targetDetailPath":"/data/v1/records/risk-sdlc-vulnerabilities-in-software-10c28b16.json","targetId":"risk:sdlc-vulnerabilities-in-software","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:c864fa00f5335636be6d821a5f146456add5940d3e01652e7dbc180a471e9624","properties":{},"sourceDetailPath":"/data/v1/records/wf-c41-f5b6a3b6.json","sourceId":"wf:C41","targetDetailPath":"/data/v1/records/uc-uc-sdlc-06-c1afc713.json","targetId":"uc:UC-SDLC-06","type":"operates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:e6a8f5a385fa28ecc7261429945fb96f9dafb9e5ff491947f66ec6472b318fc5","properties":{"rationale":"Baseline control and integrity verification of dependencies help detect malicious/backdoored third-party libraries.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-sdlc-06-c1afc713.json","sourceId":"uc:UC-SDLC-06","targetDetailPath":"/data/v1/records/risk-ai-supply-chain-concentration-9f791f54.json","targetId":"risk:ai-supply-chain-concentration","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:fe5b9be8a462f95e221741fbbcd5f0671e7d5e41e5f3f91153380f74528c4a4f","properties":{"rationale":"Tracking integrity of changes to configuration items surfaces unauthorized/malicious modification of system software.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-sdlc-06-c1afc713.json","sourceId":"uc:UC-SDLC-06","targetDetailPath":"/data/v1/records/risk-sdlc-malware-injection-compromise-ec5a8dc4.json","targetId":"risk:sdlc-malware-injection-compromise","type":"mitigates"}],"schemaVersion":1}
