Skip to main content

💼 CM-9 Configuration Management Plan

  • Contextual name: 💼 CM-9 Configuration Management Plan
  • ID: /frameworks/nist-sp-800-53-r5/cm/09
  • Located in: 💼 CM Configuration Management

Description

Develop, document, and implement a configuration management plan for the system that: a. Addresses roles, responsibilities, and configuration management processes and procedures; b. Establishes a process for identifying configuration items throughout the system development life cycle and for managing the configuration of the configuration items; c. Defines the configuration items for the system and places the configuration items under configuration management; d. Is reviewed and approved by [Assignment: organization-defined personnel or roles]; and e. Protects the configuration management plan from unauthorized disclosure and modification.

Similar

  • Internal
    • ID: dec-c-4c719b4e

Similar Sections (Give Policies To)

SectionSub SectionsInternal RulesPoliciesFlags
💼 FedRAMP High Security Controls → 💼 CM-9 Configuration Management Plan (M)(H)8
💼 NIST CSF v2.0 → 💼 ID.AM-08: Systems, hardware, software, services, and data are managed throughout their life cycles21

Sub Sections

SectionSub SectionsInternal RulesPoliciesFlags
💼 CM-9(1) Configuration Management Plan _ Assignment of Responsibility

Policies (8)

PolicyLogic CountFlags
📝 Google Cloud DNS Managed Zone DNSSEC is not enabled 🟢1🟢 x6
📝 Google Cloud DNS Managed Zone DNSSEC Key-Signing Algorithm is RSASHA1 🟢1🟢 x6
📝 Google Cloud DNS Managed Zone DNSSEC Zone-Signing Algorithm is RSASHA1 🟢1🟢 x6
📝 Google Cloud SQL Server Instance 3625 (trace flag) Database Flag is not set to on 🟢1🟢 x6
📝 Google Cloud SQL Server Instance user connections Database Flag is set to a limiting (other than 0) value 🟢1🟢 x6
📝 Google Cloud SQL Server Instance user options Database Flag is configured 🟢1🟢 x6
📝 Google Project has a default network 🟢1🟢 x6
📝 Google Project has a legacy network 🟢1🟢 x6