UCF STIG Viewer Logo

A change management policy must be implemented for application development.


Overview

Finding ID Version Rule ID IA Controls Severity
V-39441 ENTD0110 SV-51299r1_rule DCII-1 DCPR-1 Medium
Description
Change management is the formal review process that ensures that all changes made to a system or application receives formal review and approval. Change management reduces impacts from proposed changes that could possibly have interruptions to the services provided. Recording all changes for applications will be accomplished by a configuration management policy. The configuration management policy will capture the actual changes to software code and anything else affected by the change.
STIG Date
Test and Development Zone B Security Technical Implementation Guide 2015-12-17

Details

Check Text ( C-46716r3_chk )
Interview the ISSM/ISSO to determine whether a current Change Control Management policy has been implemented in the organization. If a change management policy has not been created and implemented for the organization, this is a finding.

If there isn't any application development occurring in the zone environment, this requirement is not applicable.
Fix Text (F-44454r2_fix)
Create a change management policy for the organization for application and system development.