Finding ID | Version | Rule ID | IA Controls | Severity |
---|---|---|---|---|
V-39441 | ENTD0110 | SV-51299r1_rule | DCII-1 DCPR-1 | Medium |
Description |
---|
Change management is the formal review process that ensures that all changes made to a system or application receives formal review and approval. Change management reduces impacts from proposed changes that could possibly have interruptions to the services provided. Recording all changes for applications will be accomplished by a configuration management policy. The configuration management policy will capture the actual changes to software code and anything else affected by the change. |
STIG | Date |
---|---|
Test and Development Zone A Security Technical Implementation Guide | 2015-12-17 |
Check Text ( C-46716r3_chk ) |
---|
Interview the ISSM/ISSO to determine whether a current Change Control Management policy has been implemented in the organization. If a change management policy has not been created and implemented for the organization, this is a finding. If there isn't any application development occurring in the zone environment, this requirement is not applicable. |
Fix Text (F-44454r2_fix) |
---|
Create a change management policy for the organization for application and system development. |