Skip to main content

πŸ’Ό CM-4 SECURITY IMPACT ANALYSIS

  • Contextual name: πŸ’Ό CM-4 SECURITY IMPACT ANALYSIS
  • ID: /frameworks/nist-sp-800-53-r4/cm/04
  • Located in: πŸ’Ό CM CONFIGURATION MANAGEMENT

Description​

The organization analyzes changes to the information system to determine potential security impacts prior to change implementation.

Similar​

  • Internal
    • ID: dec-c-e7152985

Similar Sections (Give Policies To)​

SectionSub SectionsInternal RulesPoliciesFlags
πŸ’Ό NIST CSF v1.1 β†’ πŸ’Ό PR.IP-1: A baseline configuration of information technology/industrial control systems is created and maintained incorporating security principles (e.g. concept of least functionality)414
πŸ’Ό NIST CSF v1.1 β†’ πŸ’Ό PR.IP-3: Configuration change control processes are in place44

Sub Sections​

SectionSub SectionsInternal RulesPoliciesFlags
πŸ’Ό CM-4 (1) SEPARATE TEST ENVIRONMENTS
πŸ’Ό CM-4 (2) VERIFICATION OF SECURITY FUNCTIONS