CM-3(1): Automated Document / Notification / Prohibition Of Changes

CSF v1.1 References:

Baselines:

  • High

Next Version:

Control Statement

The organization employs automated mechanisms to:

  1. Document proposed changes to the information system;
  2. Notify [Assignment: organized-defined approval authorities] of proposed changes to the information system and request change approval;
  3. Highlight proposed changes to the information system that have not been approved or disapproved by [Assignment: organization-defined time period];
  4. Prohibit changes to the information system until designated approvals are received;
  5. Document all changes to the information system; and
  6. Notify [Assignment: organization-defined personnel] when approved changes to the information system are completed.