CCC-06: Change Management Baseline

CSF v1.1 References:

PF v1.0 References:

Info icon.

Control is new to this version of the control set.

Control Statement

Establish change management baselines for all relevant authorized changes on organization assets.

Implementation Guidance

A change management baseline reflects the minimum policies, procedures and technical measures established to achieve organizational objectives, and requirements (i.e., CCC-02 implementation guidelines).

Auditing Guidance

  1. Examine policy and/or standards related to change management to determine if changes are formally controlled, documented and enforced to minimize the corruption of information systems.
  2. Determine if the introduction of new systems and major changes to existing systems are formally documented, specified, tested, quality controlled, and the implementation managed.

[ Note: For more information on the Cloud Controls Matrix, visit the CSA Cloud Controls Matrix Homepage.]

Cloud Control Matrix is Copyright 2023 Cloud Security Alliance.