💼 CM-4 SECURITY IMPACT ANALYSIS
- ID:
/frameworks/nist-sp-800-53-r4/cm/04
Description​
The organization analyzes changes to the information system to determine potential security impacts prior to change implementation.
Similar​
- Internal
- ID:
dec-c-e7152985
- ID:
Similar Sections (Give Policies To)​
| Section | Sub Sections | Internal Rules | Policies | Flags | Compliance |
|---|---|---|---|---|---|
| 💼 NIST CSF v1.1 → 💼 PR.IP-1: A baseline configuration of information technology/industrial control systems is created and maintained incorporating security principles (e.g. concept of least functionality) | 4 | 26 | no data | ||
| 💼 NIST CSF v1.1 → 💼 PR.IP-3: Configuration change control processes are in place | 5 | 5 | no data |
Sub Sections​
| Section | Sub Sections | Internal Rules | Policies | Flags | Compliance |
|---|---|---|---|---|---|
| 💼 CM-4 (1) SEPARATE TEST ENVIRONMENTS | no data | ||||
| 💼 CM-4 (2) VERIFICATION OF SECURITY FUNCTIONS | no data |