33. DRAFT - Template-System Level Configuration Management Plan.doc
DOC document 312 KB Posted
- Attached to
- Charleston Consolidated Storage Distribution Center Federal contract opportunity
- Solicitation number
- Not on record
About this file
This special notice document announces an upcoming solicitation for an initial outfitting project for the Charleston Consolidated Storage and Distribution Center. The U.S. Army Corps of Engineers Little Rock District intends to issue a request for quote as a total small business set-aside, with an estimated value between $1.5-2 million. Interested parties can visit the site on August 23rd, and submit any questions by August 25th. Responses are due by September 2nd, with the potential BOD on January 19th and OFB on March 19th, 2023. The special notice is being posted in advance of the solicitation due to project timelines.
View the file
Other files for this federal contract opportunity
Show all 37
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
Program Office Information System Name Configuration Management Plan Month YYYY
PROGRAM OFFICE INFORMATION SYSTEM NAME
version number
Configuration Management Plan for
[eMASS System Name]
[eMASS SYSTEM ACRONYM]
[System Version 1.5.0.0]
June 2018 Use the month and year of the Authorizing Official (AO) signature in the placeholder above.
Contact Information / Approvals System Owner:
| [Enter name] |
| [Enter date] |
Signature and date:
Information System Security Manager:
| [Enter name] |
| [Enter date] |
Signature and date:
Information System Security Officer:
| [Enter name] |
| [Enter date] |
Signature and date:
Document Revision and History Page
This document will be reviewed at a minimum annually.
| DOCUMENT VERSION # |
| REVISION DATE |
| DESCRIPTION |
OF CHANGE
SECTION/
PARAGRAPH
PAGE
| 1.0.0 |
| 29-June-2015 |
| Original Release |
| - |
| - |
| 1.1.0 |
| 06-Jan-2016 |
| Added Revision and History Page |
| Revision and History |
| i |
| 1.2.0 |
| 09-Sep-2016 |
| Administrative updates, review of references, etc. |
| Global |
| Global |
| 1.3.0 |
| 21-Feb-2017 |
| Administrative updates, review of references, etc. |
| Global |
| Global |
| 1.4.0 |
| 15-Apr-2017 |
| Administrative updates, review of references, etc. |
Revamping of Contingency Planning Controls Table
Re-organization
Addition of CCI tables
Acronym List Updated Global
Pg. 1-2
Global
Global
Pg. 1-2 Global
Pg. 1-2
Global
Global
Pg. 1-2
| 1.5.0 |
| 21 June-2018 |
| Annual Update/ Review |
Removal of CCIs that are addressed within the T1 and T2 SOR
| Global |
| Global |
Table of Contents
1GENERAL INFORMATION
1CONFIGURATION MANAGEMENT PLAN
1PURPOSE
2SCOPE
2HOW TO USE THIS GUIDE
INTRODUCTION
31.1 Configuration Management Controls
31.2 Scope
41.3 Purpose
51.4 Applicable Provisions and Directives
SYSTEM OVERVIEW
72.1 System Architecture
82.2 Information System Component Inventory [CM-8]
92.3 No Duplicate Accounting of Components [CM-8(5)]
92.4 Automated Unauthorized Component Detection [CM-8(3)]
102.5 Configure Systems, Components, or Devices for High Risk Areas [CM-2(7)]
CONFIGURATION PROGRAM
123.1 Configuration Change Control [CM-3; CM-9]
123.2 Configuration Control Board (CCB)
153.3 Change Request
153.4 Initial Request Evaluation
163.5 CCB Courses of Action
163.6 Unscheduled Changes
163.7 Test Validate and Document Changes [CM-3 (2); CM-9]
173.8 Security Impact Analysis [CM-4]
183.9 Configuration Status Accounting
183.10 Access Restrictions for Change [CM-5; CM-9]
193.11 Configuration Settings [CM-6]
203.12 Configuration Audits
203.13 Least Functionality [CM-7]
213.14 Periodic Review [CM-7(1)]
213.15 Prevent Program Execution [CM-7(2)]
223.16 Unauthorized Software Blacklisting [CM-7(4)]
223.17 Information System Component Inventory [CM-8]
233.18 CM Plan Maintenance
24APPENDIX A: ACRONYM LIST
25APPENDIX B: CCB CHARTER
26APPENDIX C: CHANGE REQUEST FORM TEMPLATE
LisT of Tables 3Table 1-1: Summary of NIST SP 800-53: Configuration Management Plan Controls
15Table 3‑1: Configuration Management Roles and Responsibilities
GENERAL INFORMATION
Configuration Management (CM) is the ongoing process of identifying and managing changes to deliverables and other work products. It is a systems development discipline that promotes the proper identification of the configuration, control of changes, and records the change implementation status of the physical and functional characteristics of an Information Technology (IT) system. Configuration Management identifies what is required, designed, and produced. It also provides for the evaluation of changes including effects on technical and operational performance. This leads to making the configuration visible and understood by all the parties involved with the system.
Configuration management covers three basic essential interdependent activities:
1) Configuration Identification – Configuration identification is for the formal step of identifying the configuration of an item (i.e., name, location, version), and documenting its functional and physical characteristics.
2) Configuration Control – Configuration control is the exercising of established procedures to classify, approve or disapprove, implement, and confirm changes to the agreed upon specifications and baselines.
3) Configuration Management Status Accounting – Configuration accounting is the formal recording and reporting of data relating to configuration identification, approval status of proposed changes, and implementation status of approved changes during all phases of the project.
Configuration Management is therefore the means through which integrity and continuity of the system’s design, and decisions made regarding technical performance, producibility, operability, and supportability are recorded, communicated, and controlled.
CONFIGURATION MANAGEMENT PLAN
A Configuration Management Plan (CMP) is developed to define, document, control, implement, account for, and audit changes to the various components of an IT system. The CMP:
· Provides information on the requirements and procedures necessary for CM activities
· Establishes the methodology for configuration identification and control of releases and changes to configuration items (CI)
· Describes the process for maintaining status accounting and verifying the completeness and correctness of CIs throughout the system lifecycle
A CMP must identify and describe the overall policies and methods for the CM activities to be used during a system’s life cycle.
PURPOSE
This CMP Development Guide provides the framework to identify and describe the overall policies and methods for CM activities to be used during a system’s life cycle. The final CMP product should be delivered in electronically searchable format using an approved documentation presentation. It must be able to stand on its own with all elements explained and acronyms spelled out for reader/reviewers who may not be familiar with the system.
SCOPE
This CMP is a tool used to establish the overall approach for the Configuration Management requirement for the applicable infrastructure system. The CMP will be a dynamic document, and will be updated as work on the system proceeds and the necessity arises.
HOW TO USE THIS GUIDE
The instructions in Sections 1.0 – 3.18 of this document must be adhered to in developing Configuration Management Plans (CMP) for DHA infrastructure systems. This document was developed to ensure that CMPs created using its guidance comply with governing mandates, to include the DHA Risk Management Framework (RMF) requirements.
The structure of the CMP outline provided in Sections 1.0 – 3.18 follows industry standards and best practices for configuration management plans, ensuring the minimum content requirements will be included in the completed artifact. The completed CMP should be structured to allow for discrete sections to cover specific CM activities, all of which are accounted for in the provided CMP outline.
To enhance the utility of the CMP, additional sections/sub-sections may be added, however the content for Sections 1.0 – 3.18 cannot be omitted from the final site CMP. Instructional content is identified by Red text throughout the CMP outline and must be included in the CMP.
1 INTRODUCTION
Example Text: Configuration Management (CM) is the implementation and execution of processes and procedures that ensure the systematic and orderly control of a system and its components throughout its life cycle. CM ensures system integrity by controlling changes to the components of a system.
Configuration Management can be applied at many levels of a system, from subsystem to system and networks of systems. At the system level, configuration management of Department of Defense (DoD) systems requires a focus on secure configurations.
1.1 Configuration Management Controls
The Security Control table identifies controls applicable to Information System (IS) Name ACRONYM.
NOTE: The following Configuration Management Plan controls below are from NIST SP 800-53, Rev. 4. This table will assist you in identifying controls that are applicable to your system. Do not delete any rows in the Table 1-1 below.
If any controls are identified as “Not applicable”, please state “Not applicable” in the section within this document. Do not delete any section within this document.
Delete this notational text box before submitting to DHA CSD for approval.
| Control No. |
| Control Name |
| Applicability |
Select one and delete the other; then change to black font
| CM-1 |
| Configuration Management Policy and Procedures |
| Yes No |
| CM-2 |
| Baseline Configuration |
| Yes No |
| CM-3 |
| Configuration Change Control |
| Yes No |
| CM-4 |
| Security Impact Analysis |
| Yes No |
| CM-5 |
| Access Restrictions for Change |
| Yes No |
| CM-6 |
| Configuration Settings |
| Yes No |
| CM-7 |
| Least Functionality |
| Yes No |
| CM-9 |
| Configuration Management Plan |
| Yes No |
Table 1-1: Summary of NIST SP 800-53: Configuration Management Plan Controls
1.2 Scope
The Configuration Management Plan describes a tiered approach and organizational framework for implementing and providing oversight of CM processes and controls. Detailed operational processes are to be defined and documented in specific tier level plans, such as CCB Charters.
1.3 Purpose
Configuration Management Policy, Procedures, and Plan [CM-1, CM-9] This Configuration Management Plan (CMP) describes how configuration management will be conducted for the (Program Office/Contractor Name Abbreviation Information System (IS)). This document is intended to be used for the management and control of (Program Office/Contractor Name Abbreviation IS) configurations to enable security and facilitate the management of risk. This CMP is to be used by (Program Office/Contractor Name Abbreviation IS) program personnel as a reference in defining and implementing the operational CM plans and processes by documenting:
1) Formally documented CM roles, responsibilities, and procedures, management commitment, coordination among organizational entities, and compliance
2) A configuration control board that implements procedures to ensure a security review and approval of all proposed DoD information system changes, to include interconnections to other DoD information systems;
3) A testing process that verifies proposed configuration changes prior to implementation in the operational environment ; and
4) A verification process that provides additional assurance that the CM process is working effectively and that the changes outside of the CM process are technically or procedurally not permitted.
CM-1 – Configuration Management Policy And Procedures
| CCI |
| Description |
| Implementation Procedures |
If not applicable, enter the following:
This CCI is not applicable.
| CCI-000287 |
| The organization develops and documents a configuration management policy that addresses purpose, scope, roles, responsibilities, management commitment, coordination among organizational entities, and compliance. |
| CCI-000290 |
| The organization develops and documents procedures to facilitate the implementation of the configuration management policy and associated configuration management controls. |
| CCI-000292 |
| The organization reviews and updates, on an organization defined frequency, the procedures to facilitate the implementation of the configuration management policy and associated configuration management controls. |
| CCI-000289 |
| The organization reviews and updates, on an organization defined frequency, the configuration management policy. |
| CCI-001822 |
| The organization disseminates the configuration management policy to organization defined personnel or roles. |
| CCI-001825 |
| The organization disseminates to organization defined personnel or roles the procedures to facilitate the implementation of the configuration management policy and associated configuration management controls. |
CM-9 – Configuration Management Plan
| CCI |
| Description |
| Implementation Procedures |
If not applicable, enter the following:
This CCI is not applicable.
| CCI-000421 |
| The organization develops and documents a configuration management plan for the information system that addresses roles, responsibilities, and configuration management processes and procedures. |
| CCI-000423 |
| The organization implements a configuration management plan for the information system that addresses roles, responsibilities, and configuration management processes and procedures. |
The organization being assessed develops, documents, and annually maintains procedures to facilitate the implementation of the configuration management policy and associated configuration management controls. All updates and review occurrences must be documented.
The organization disseminates a configuration management policy to all stakeholders in the configuration management process to facilitate implementation.
1.4 Applicable Provisions and Directives
Example Text: The CMP is developed in accordance with Federal, Department of Defense (DoD), and Defense Health Agency (DHA) guidance:
STANDARD References:
· DoD Instruction 8500.01, “Cybersecurity”, 14 March 2014
· (DoD) Instruction 8510.01, “Risk Management Framework (RMF) for DoD Information Technology (IT)”, 12 March 2014 Incorporating Change 2, 28 July 2017
· DoDI 8551.01. “Ports Protocols and Services Management” 28 May 2014
· NIST SP 800-53 “Security and Privacy Controls for Federal Information Systems and Organizations”, Rev 4, April 2013
· NIST SP 800-128, "Guide for Security Focused Configuration Management of Information Systems", August 2011
2 SYSTEM OVERVIEW
Provide an overview of the system. Ensure this description is consistent with other Artifacts that contain a system overview description. (Use System description from SP)
2.1 System Architecture
Hardware and Software Baseline [CM-2, CM-2(1), CM-2(3), CM-8, CM-8(1)] The organization documents a current baseline configuration of the information system and maintains updates under configuration control. Baseline Document reviews must be conducted annually, upon any baseline configuration change, component installation, component upgrades, and component removals or as events or circumstances dictate. Previous versions of the baseline configurations of the information system and components are retained for a minimum of 3 months to support rollback.
CM-2 – Baseline Configuration
| CCI |
| Description |
| Implementation Procedures |
If not applicable, enter the following:
This CCI is not applicable.
| CCI-00293 |
| The organization develops and documents a current baseline configuration of the information system. |
| CCI-000295 |
| The organization maintains under configuration control, a current baseline configuration of the information system. |
CM-2 (1) – Baseline Configuration | Reviews And Updates
| CCI |
| Description |
| Implementation Procedures |
If not applicable, enter the following:
This CCI is not applicable.
| CCI-000296 |
| The organization reviews and updates the baseline configuration of the information system at an organization-defined frequency. |
| CCI-000297 |
| The organization reviews and updates the baseline configuration of the information system when required due to organization-defined circumstances. |
| CCI-000298 |
| The organization reviews and updates the baseline configuration of the information system as an integral part of information system component installations. |
| CCI-000299 |
| The organization reviews and updates the baseline configuration of the information system as an integral part of information system component upgrades. |
CM-2(3) – Baseline Configuration | Retention Of Previous Configurations
| CCI |
| Description |
| Implementation Procedures |
If not applicable, enter the following:
This CCI is not applicable.
| CCI-000304 |
| The organization retains organization-defined previous versions of baseline configurations of the information system to support rollback. |
CM-8 – Information System Component Inventory
| CCI |
| Description |
| Implementation Procedures |
If not applicable, enter the following:
This CCI is not applicable.
| CCI-001780 |
| The organization reviews and updates the information system component inventory per organization-defined frequency. |
CM-8(1) – Information System Component Inventory | Updates During Installations / Removals
| CCI |
| Description |
| Implementation Procedures |
If not applicable, enter the following:
This CCI is not applicable.
| CCI-000408 |
| The organization updates the inventory of information system components as an integral part of component installations. |
| CCI-000409 |
| The organization updates the inventory of information system components as an integral part of component removals. |
| CCI-000410 |
| The organization updates the inventory of information system components as an integral part of information system updates. |
2.2 Information System Component Inventory [CM-8]
The organization develops and documents an inventory of information system components that includes all components within the authorization boundary of the information system; at a necessary granularity level for tracking and reporting.
A current and comprehensive baseline inventory of all hardware and software (HW/SW) (to include manufacturer, type, model, physical location, network topology or architecture, version, and installation manuals and procedures) is maintained by the CCB as part of the Authorization Package. A backup copy of the inventory is stored in a fire-rated container or otherwise not collocated with the original.
CM-8 – Information System Component Inventory
| CCI |
| Description |
| Implementation Procedures |
If not applicable, enter the following:
This CCI is not applicable.
| CCI-000392 |
| The organization develops and documents an inventory of information system components that includes all components within the authorization boundary of the information system. |
| CCI-000395 |
| The organization develops and documents an inventory of information system components that is at the level of granularity deemed necessary for tracking and reporting. |
| CCI-000398 |
| The organization defines information deemed necessary to achieve effective information system component accountability. |
| CCI-000399 |
| The organization develops and documents an inventory of information system components that includes organization defined information deemed necessary to achieve effective information system component accountability. |
2.3 No Duplicate Accounting of Components [CM-8(5)]
The organization verifies that all components within the authorization boundary of the information system are not duplicated in other information system inventories.
CM-8(5) – Information System Component Inventory | No Duplicate Accounting Of Components
| CCI |
| Description |
| Implementation Procedures |
If not applicable, enter the following:
This CCI is not applicable.
| CCI-000419 |
| The organization verifies that all components within the authorization boundary of the information system are not duplicated in other information system inventories. |
2.4 Automated Unauthorized Component Detection [CM-8(3)]
The organization continuously employs automated mechanisms to detect the presence of unauthorized hardware, software, and firmware components within the information system and defines personnel and roles to be notified of such findings.
The organization takes action to disable network access by such components, isolates the components, notifies organization-defined personnel and documents all related activity.
CM-8(3) – Information System Component Inventory | Automated Unauthorized Component Detection
| CCI |
| Description |
| Implementation Procedures |
If not applicable, enter the following:
This CCI is not applicable.
| CCI-001783 |
| The organization defines the personnel or roles to be notified when unauthorized hardware, software, and firmware components are detected within the information system. |
| CCI-001784 |
| When unauthorized hardware, software, and firmware components are detected within the information system, the organization takes action to disable network access by such components, isolates the components, and/or notifies organization-defined personnel or roles. |
2.5 Configure Systems, Components, or Devices for High Risk Areas [CM-2(7)] The organization defines and documents, in the configuration management policy, the security configurations to be implemented on information systems, system components, or devices when they are located in areas of significant risk or to individuals traveling to locations the organization deems to be of significant risk.
The organization defines and applies security safeguards to devices when individuals return from areas of significant risk.
CM-2(7) – Baseline Configuration | Configure Systems, Components, Or Devices For High-Risk Areas
| CCI |
| Description |
| Implementation Procedures |
If not applicable, enter the following:
This CCI is not applicable.
| CCI-001737 |
| The organization defines the information systems, system components, or devices that are to have organization-defined configurations applied when located in areas of significant risk. |
| CCI-001738 |
| The organization defines the security configurations to be implemented on information systems, system components, or devices when they are located in areas of significant risk. |
| CCI-001739 |
| The organization issues organization-defined information systems, system components, or devices with organization-defined configurations to individuals traveling to locations the organization deems to be of significant risk. |
| CCI-001815 |
| The organization defines the security safeguards to be applied to devices when they return from areas of significant risk. |
| CCI-001816 |
| The organization applies organization-defined security safeguards to devices when individuals return from areas of significant risk. |
3 CONFIGURATION PROGRAM
3.1 Configuration Change Control [CM-3; CM-9]
Configuration control is the process of requesting, evaluating, approving or disapproving proposed changes, and implementing approved changes to the system or subsystem baselines. Configuration control extends throughout the system life cycle.
3.2 Configuration Control Board (CCB)
The Configuration Control Board (CCB) is responsible for maintaining configuration control over Configuration Items (CI’s) in the product baselines. In addition, they are responsible for administering the process by which requests for change to products under control is submitted, reviewed, and approved or disapproved.
The CCB plays an important role as gate keeper in deciding which changes may be acted upon and introduced into an information system. The CCB deliberately considers the potential effect of proposed change on the functionality and secure state of the information system and risk to the mission if the change is implemented or not implemented. By reviewing each proposed and implemented modification, the CCB ensures that there is a disciplined, systematic, and secure approach for introducing change. Having a clearly defined process or framework for the evaluation and approval of change requests (CR), including predefined evaluation criteria, helps to ensure that each proposed and implemented change is evaluated in a consistent and repeatable manner balancing security, business, and technical viewpoints.
The CCB defines within their CCB Charter, the frequency and conditions for configuration change control review and will maintain and review an audit trail of each proposed and decided configuration controlled change.
The CCB determines the types of changes to the information system (configuration items) that are configuration controlled, throughout the system development life cycle and the time period in which records of the changes are retained.
CM-3 – Configuration Change Control
| CCI |
| Description |
| Implementation Procedures |
If not applicable, enter the following:
This CCI is not applicable.
| CCI-000314 |
| The organization approves or disapproves configuration controlled changes to the information system with explicit consideration for security impact analysis. |
| CCI-000318 |
| The organization audits and reviews activities associated with configuration controlled changes to the system. |
| CCI-000319 |
| The organization coordinates and provides oversight for configuration change control activities through an organization defined configuration change control element (e.g., committee, board) that convenes at the organization defined frequency and/or for any organization defined configuration change conditions. |
| CCI-000320 |
| The organization defines frequency to convene configuration change control element. |
| CCI-000321 |
| The organization defines configuration change conditions that prompt the configuration change control element to convene. |
| CCI-001740 |
| The organization reviews proposed configuration controlled changes to the information system. |
| CCI-001741 |
| The organization documents configuration change decisions associated with the information system. |
| CCI-001819 |
| The organization implements approved configuration-controlled changes to the information system. |
| CCI-000313 |
| The organization determines the types of changes to the information system that are configuration controlled. |
| CCI-000316 |
| The organization retains records of configuration-controlled changes to the information system for an organization-defined time period. |
CM-9 – Configuration Management Plan
| CCI |
| Description |
| Implementation Procedures |
If not applicable, enter the following:
This CCI is not applicable.
| CCI-000424 |
| The organization develops and documents a configuration management plan for the information system that defines the configuration items for the information system. |
| CCI-000426 |
| The organization implements a configuration management plan for the information system that defines the configuration items for the information system. |
| CCI-001790 |
| The organization develops and documents a configuration management plan for the information system that establishes a process for identifying configuration items throughout the system development life cycle. |
| CCI-001792 |
| The organization implements a configuration management plan for the information system that establishes a process for identifying configuration items throughout the system development life cycle. |
| CCI-001796 |
| The organization develops and documents a configuration management plan for the information system that places the configuration items under configuration management. |
| CCI-001798 |
| The organization implements a configuration management plan for the information system that places the configuration items under configuration management |
| Role |
| Responsibility |
| Subject Matter Expert |
| · Create a Change Request and forward it to CCB members for review |
· Submit additional input and information
· Provide information regarding hardware/software changes and impacts to the system
| Information System Security Officer |
| · Review and evaluate changes to ensure the integrity of the system. |
· Review the change process to ensure that the modified configuration maintains its authorization status
· Review and evaluate proposed changes to ensure that the proposed changes are in accordance with DoD security policy and guidance as well as applicable federal laws, directives, policies, regulations, standards, and guidance.
· Notify the AO of significant changes that may impact the IA posture of the system
| Information System Security Manager |
| · Review and evaluate changes to ensure the integrity of the system. |
· Review the change process to ensure that the modified configuration maintains its authorization status
· Review and evaluate proposed changes to ensure that the proposed changes are in accordance with DoD security policy and guidance as well as applicable federal laws, directives, policies, regulations, standards, and guidance.
· Notify the ISSO of significant changes that may impact the IA posture of the system
| System Owner |
| · Evaluate proposed changes based on inputs form the CCB and determine action |
| Project Manager |
| · Coordinate proposed changes submitted and approved with the technical team |
· Assist the CCB members in determining the impact of proposed changes as a subject matter expert where appropriate
Table 3‑1: Configuration Management Roles and Responsibilities
3.3 Change Request
The proposed changes are initiated in a change request (CR). CR’s may be initiated by any member of the program team. A CR documents pertinent information including, the configuration item name, configuration baseline version, requested change, justification for the change, impact of the proposed change, who is requesting the change, etc. Additional information may be gathered by members of the program team or CCB to effectively evaluate the CR. A sample Change Request Form is provided in Appendix (x). CR’s are tracked by a unique ID to ensure accountability, control, traceability to implementation, and auditability.
3.4 Initial Request Evaluation
The evaluation of a change is an important activity of the change request process to validate justification for the change and assess the impact of the proposed change to the system, affected configuration items schedule and budget. The scope and degree of formality for the evaluation process depends on the impact of the change.
The first step is to determine if the change requires configuration control. Some types of changes may be exempt from configuration control or pre-approved as defined by the CCB. If the change is exempt or pre-approved it is noted on the change request and the change is made without further analysis or approval; however, system documentation may still require updating (e.g. the Security Plan, the baseline configuration, component inventory, etc.)
Significant changes may require multiple steps for review, evaluation, and recommendation. Small changes may combine steps to shorten and simplify the process. Best practices for configuration change control require that changes to the information system be vetted by at least one authorized individual who is independent of the requestor.
3.5 CCB Courses of Action
The CCB evaluates each CR. The requestor, technical personnel, or subject matter experts may be called on to explain their position on the request.
For each CR, the CCB has three courses of action:
· Approve. The proposed change is approved and may be scheduled for implementation. The CCB may determine the schedule or leave it to the Technical Manager to implement it when appropriate.
· Deny. The proposed change may not be implemented.
· Defer. The CCB does not make a decision at this point in time. It may determine a time period when it will consider the request again, or leave scheduling for further consideration.
3.6 Unscheduled Changes
Situations may arise that necessitate and unscheduled (emergency) change. It is incumbent upon information system owners to identify all sources of the change to make sure that changes requiring configuration control go through the configuration change control process. Unscheduled changes are reviewed/resolved by the CCB as soon as is practical after unscheduled changes are made.
3.7 Test Validate and Document Changes [CM-3 (2); CM-9]
Once the change has been analyzed and approved, it is tested. A comprehensive set of procedures exist to make sure that it is implemented and test all patches and upgrades prior to deployment.
The organization documents and implements a process to test changes to the information system before implementing the changes on the operational system and maintain an audit trail of testing activity.
The organization documents and validates all changes to the information system before the changes are implemented on the operational system.
The change is then implemented, verified and applicable updates are made to supporting documents, such as technical designs and baseline configurations, the new baseline becomes the current version, and the previous baseline is no longer valid, but is retained for historical purposes. If there are any issues with a production release, retention of previous versions allows for a rollback or restoration to a previous secure and functional version of the baseline configuration. Additionally, archiving previous baseline configurations is useful for incident response and traceability support during formal audits.
CM-3(2) – Configuration Change Control | Test / Validate / Document Changes
| CCI |
| Description |
| Implementation Procedures |
If not applicable, enter the following:
This CCI is not applicable.
| CCI-000327 |
| The organization tests changes to the information system before implementing the changes on the operational system. |
| CCI-000328 |
| The organization validates changes to the information system before implementing the changes on the operational system. |
| CCI-000329 |
| The organization documents changes to the information system before implementing the changes on the operational system |
CM-9 – Configuration Management Plan
| CCI |
| Description |
| Implementation Procedures |
If not applicable, enter the following:
This CCI is not applicable.
| CCI-001793 |
| The organization develops and documents a configuration management plan for the information system that establishes a process for managing the configuration of the configuration items. |
| CCI-001795 |
| The organization implements a configuration management plan for the information system that establishes a process for managing the configuration of the configuration items. |
3.8 Security Impact Analysis [CM-4]
It is only when proposed changes are evaluated for their security impact that the configuration change control process yields benefits for the security posture of the information system. A security impact analysis is conducted by individuals or teams within the CCB that possess the technical knowledge of the information system.
The CCB records its analysis of changes to the information system to determine potential security impacts prior to change implementation.
CM-4 – Security Impact Analysis
| CCI |
| Description |
| Implementation Procedures |
If not applicable, enter the following:
This CCI is not applicable.
| CCI-000333 |
| The organization analyzes changes to the information system to determine potential security impacts prior to change implementation. |
3.9 Configuration Status Accounting
Configuration Status Accounting (CSA) is the recording and reporting of information needed to manage CI’s effectively. CSA includes:
· A record of the approved configuration documentation and identification numbers
· The status of proposed changes, deviations, and waivers to configuration
· The implementation status of approved changes
· The configuration of all units of the CI in the operational inventory
· Results of audits
CSA documentation is the means through which actions affecting CI’s are recorded and reported to interested parties. CM Managers have the primary responsibility for managing, compiling, maintaining, and publishing CSA records and reports. The records and reports provide status information to program management that the changes between the system description and the system itself are being accounted for on a one-to-one relationship. The CM Manager determines the frequency of the distribution and recipients of the CSA reports.
3.10 Access Restrictions for Change [CM-5; CM-9]
The organization defines, documents, approves, and enforces both physical and logical access restrictions associated with changes to the information system.
The organization must document the plan implementations to protect the configuration management plan from unauthorized disclosure and modification, so that all changes to the CM Plan are approved. Measures must include marking, labeling, and handling to prevent improper disclosure.
CM-5 – Access Restrictions for Change
| CCI |
| Description |
| Implementation Procedures |
If not applicable, enter the following:
This CCI is not applicable.
| CCI-000338 |
| The organization defines physical access restrictions associated with changes to the information system. |
| CCI-000339 |
| The organization documents physical access restrictions associated with changes to the information system. |
| CCI-000340 |
| The organization approves physical access restrictions associated with changes to the information system. The organization enforces physical access restrictions associated with changes to the information system. |
| CCI-000341 |
| The organization enforces physical access restrictions associated with changes to the information system. |
| CCI-000342 |
| The organization defines logical access restrictions associated with changes to the information system. |
| CCI-000343 |
| The organization documents logical access restrictions associated with changes to the information system. |
| CCI-000344 |
| The organization approves logical access restrictions associated with changes to the information system. |
| CCI-000345 |
| The organization enforces logical access restrictions associated with changes to the information system. |
CM-9 – Configuration Management Plan
| CCI |
| Description |
| Implementation Procedures |
If not applicable, enter the following:
This CCI is not applicable.
| CCI-001799 |
| The organization develops a configuration management plan for the information system that protects the configuration management plan from unauthorized disclosure and modification. |
| CCI-001801 |
| The organization implements a configuration management plan for the information system that protects the configuration management plan from unauthorized disclosure and modification. |
3.11 Configuration Settings [CM-6]
The organization documents and implements the use of DoD STIGS for the deployment of acquired IA-enabled products and the establishment of their configuration settings.
The organization identifies, documents, and approves any deviations from the established configuration settings for information system components based on organization-defined operational requirements.
The organization documents, monitors and controls changes to the configuration settings.
CM-6 – Configuration Settings
| CCI |
| Description |
| Implementation Procedures |
If not applicable, enter the following:
This CCI is not applicable.
| CCI-000363 |
| The organization defines security configuration checklists to be used to establish and document configuration settings for the information system technology products employed. |
| CCI-000366 |
| The organization implements the security configuration settings. |
| CCI-000367 |
| The organization identifies any deviations from the established configuration settings for organization-defined information system components based on organization-defined operational requirements. |
| CCI-000368 |
| The organization documents any deviations from the established configuration settings for organization-defined information system components based on organization-defined operational requirements. |
| CCI-000369 |
| The organization approves any deviations from the established configuration settings for organization-defined information system components based on organization-defined operational requirements. |
| CCI-001756 |
| The organization defines the operational requirements on which the configuration settings for the organization-defined information system components are to be based. |
| CCI-001502 |
| The organization monitors changes to the configuration settings in accordance with organizational policies and procedures. |
| CCI-001503 |
| The organization controls changes to the configuration settings in accordance with organizational policies and procedures. |
3.12 Configuration Audits
Configuration audits validate that the design and the final product conform to approved functional requirements, as defined in applicable specifications and drawings, and that the changes have been incorporated.
3.13 Least Functionality [CM-7]
The organization is compliant/non-compliant with the DoD defined information system prohibited or restricted functions, ports, protocols, and/or services.
The organization configures the information system to provide only those documented essential capabilities.
CM-7 – Least Functionality
| CCI |
| Description |
| Implementation Procedures |
If not applicable, enter the following:
This CCI is not applicable.
| CCI-000381 |
| The organization configures the information system to provide only essential capabilities. |
| CCI-000382 |
| The organization configures the information system to prohibit or restrict the use of organization-defined functions, ports, protocols, and/or services. |
CM-7(1) –Least Functionality | Periodic Review
| CCI |
| Description |
| Implementation Procedures |
If not applicable, enter the following:
This CCI is not applicable.
| CCI-001761 |
| The organization defines the functions, ports, protocols and services within the information system that are to be disabled when deemed unnecessary and/or nonsecure. |
| CCI-001762 |
| The organization disables organization-defined functions, ports, protocols, and services within the information system deemed to be unnecessary and/or nonsecure. |
3.14 Periodic Review [CM-7(1)]
The organization documents and implements a process to review the information system every 30 days to identify unnecessary and non-secure functions, ports, protocols, and services.
CM-7(1) –Least Functionality | Periodic Review
| CCI |
| Description |
| Implementation Procedures |
If not applicable, enter the following:
This CCI is not applicable.
| CCI-000384 |
| The organization reviews the information system per organization defined frequency to identify unnecessary and nonsecure functions, ports, protocols, and services. |
3.15 Prevent Program Execution [CM-7(2)]
The organization documents its compliance with DoDI 8551 and only allows DoD approved network capable software programs to be used within the information system.
The organization configures the information system to prevent the execution of programs not authorized in accordance with DoDI 8551.
CM-7(2) –Least Functionality | Prevent Program Execution
| CCI |
| Description |
| Implementation Procedures |
If not applicable, enter the following:
This CCI is not applicable.
| CCI-001592 |
| The organization defines the rules authorizing the terms and conditions of software program usage on the information system. |
| CCI-001763 |
| The organization defines the policies regarding software program usage and restrictions |
| CCI-001764 |
| The information system prevents program execution in accordance with organization-defined policies regarding software program usage and restrictions, and/or rules authorizing the terms and conditions of software program usage. |
3.16 Unauthorized Software Blacklisting [CM-7(4)]
The organization defines and identifies the software programs not authorized to execute on the information system; and documents a review of the identified list on a monthly basis.
CM-7(4) –Least Functionality | Unauthorized Software Blacklisting
| CCI |
| Description |
| Implementation Procedures |
If not applicable, enter the following:
This CCI is not applicable.
| CCI-001765 |
| The organization defines the software programs not authorized to execute on the information system. |
| CCI-001766 |
| The organization identifies the organization-defined software programs not authorized to execute on the information system. |
| CCI-001767 |
| The organization employs an allow-all, deny-by-exception policy to prohibit the execution of unauthorized software programs on the information system. |
| CCI-001770 |
| The organization reviews and updates the list of unauthorized software programs per organization-defined frequency. |
3.17 Information System Component Inventory [CM-8]
The organization develops and documents an inventory of information system components that includes all components within the authorization boundary of the information system; at a necessary granularity level for tracking and reporting.
CM-8 –Information System Component Inventory
| CCI |
| Description |
| Implementation Procedures |
If not applicable, enter the following:
This CCI is not applicable.
| CCI-000392 |
| The organization develops and documents an inventory of information system components that includes all components within the authorization boundary of the information system. |
| CCI-000395 |
| The organization develops and documents an inventory of information system components that is at the level of granularity deemed necessary for tracking and reporting. |
3.18 CM Plan Maintenance
Configuration Mangers review configuration management policies and processes, at least annually, to ensure that all CM processes are up to date and comply with pertinent DoD policies. All changes will be incorporated as a document revision. Updates to this document are recorded on the Version History section of this document.
APPENDIX A: ACRONYM LIST
Acronyms used specifically in this Artifact are to be listed in this appendix.
| ACRONYM |
| TERM |
| AIS |
| Automated Information System |
| CCB |
| Configuration Control Board |
| CCI |
| Control Correlation Identifier |
| CI |
| Configuration Item |
CM
Configuration Management
| CMP |
| Configuration Management Plan |
| CR |
| Change Request |
| CSA |
| Configuration Status Accounting |
| DHA |
| Defense Health Agency |
| DoD |
| Department of Defense |
| HW/SW |
| Hardware/Software |
| IA |
| Information Assurance |
IS
Information System
| ISSM |
| Information System Security Manager |
| ISSO |
| Information System Security Officer |
| IT |
| Information Technology |
| NIST |
| National Institute of Standards and Technology |
| STIGS |
| Security Technical Implementation Guides |
APPENDIX B: CCB CHARTER
INSERT YOUR CCB CHARTER HERE
APPENDIX C: CHANGE REQUEST FORM TEMPLATE
The following is a sample template for a Configuration Management Change Request artifact that can be used within a SecCM program. Organizations are encouraged to adapt it to suit their needs. Please be as concise as possible.
CONFIGURATION CHANGE REQUEST FORM
Date Prepared: MMM/DD/YYYY Title of Change Request:
Change Initiator/Project Manager:
Change Description:
Change Justification:
Urgency of Change: Scheduled/Urgent/Unscheduled IS Components/CIs to be Changed:
Other IS Components, CIs, or Systems to Be Affected by Change:
Personnel involved with the Change:
Expected Security Impact of Change:
Expected Functional Impact of Change:
Expected Impact of Not Doing Change:
Potential Interface/Integration Issues:
Required Changes to Existing Applications:
Project work plan including change implementation date, deliverables, and back-out plan:
Funding Required to Implement Change:
The Configuration Management Change Request has been Approved/Disapproved. The CM Change Request has been rejected due to enter justification.
Authorized Signature(s):
Title:
Date:
Add appropriate classification marking
FOR OFFICIAL USE ONLY
File details come from the government source that posted it. Updated .