33. DRAFT - Template-System Level Configuration Management Plan.doc

DOC document 312 KB Posted

Attached to
Charleston Consolidated Storage Distribution Center Federal contract opportunity
Solicitation number
Not on record
Issued by
Department of the Army Corps of Engineers Engineering District Little Rock

About this file

This special notice document announces an upcoming solicitation for an initial outfitting project for the Charleston Consolidated Storage and Distribution Center. The U.S. Army Corps of Engineers Little Rock District intends to issue a request for quote as a total small business set-aside, with an estimated value between $1.5-2 million. Interested parties can visit the site on August 23rd, and submit any questions by August 25th. Responses are due by September 2nd, with the potential BOD on January 19th and OFB on March 19th, 2023. The special notice is being posted in advance of the solicitation due to project timelines.

View the file

Other files for this federal contract opportunity

Other files attached to Charleston Consolidated Storage Distribution Center, newest first.
File Type Posted
7. DRAFT - CSDC GC Schedule 30Jun22.pdf PDF
11. DRAFT - JSN U0096 3-phase 480 VAC Powered Battery Charger For JSN U0060 Electric Forklift.pdf PDF
2. Base Access WORKSHEET V9_Dec20_ACC (002).pdf PDF
30. DRAFT - Template-DHA-FE FRCS Vendor Risk Assessment_v2.0.docx DOCX document
17. DRAFT - DHA 27 41 43 Audio Video Conferencing.pdf PDF
16. DRAFT - Checklist_Control System Factory Acceptance Test and Site Acceptance Test.pdf PDF
9. DRAFT - JB Charleston CSDC_Existing Inventory_ 23Mar22.pdf PDF
29. DRAFT - Template-DHA RMF System Enterprise and Information Security Architecture.pdf PDF
26. DRAFT - Template_DHA RMF System Authorization Boundary.pdf PDF
0. DRAFT - SOW-FY22. IOT RD_PN89902_CSDC Charleston_2022.08.05.docx DOCX document
23. DRAFT - DHA RMF Information Flow Diagram.pdf PDF
14. DRAFT - JBCHS IDEA FONSI-FONPA_A7 Signed (2).pdf PDF
3. DRAFT - Charleston CSDC IOT Project Status Report (PSR).xlsx XLSX spreadsheet
19. DRAFT - DHA ACAS-NESSUS Scanning Guide-CUI.pdf PDF
12. DRAFT - DHA FE Wayfinding Guidelines-Signage Standards (Draft)_01Mar22.pdf PDF
11. DRAFT - JSN U1021 Wall-MountedWireGuidanceSystemLineDriverandGuidanceControlWire-Forklift(JSN U0060).pdf PDF
5. DRAFT - Interiors_JBC CSDC - DP2 FINAL_drawings.pdf PDF
1. DRAFT - Drawings Installation Map - CSDS and ACC.pdf PDF
8. DRAFT - JB Charleston CSDC_PRCL_v.2_21Jan21.pdf PDF
20. DRAFT - DHA FRCS Baseline Categorization Memorandum-1 Oct 2020.pdf PDF
0. DRAFT FY22 IOT CSDC_Div 00_CLIN BID Schedule.xlsx XLSX spreadsheet
15. DRAFT - JB Charleston CSDC_Facility Site Approval.pdf PDF
13. DRAFT - JB Charleston CSDC_Program for Design_5Feb22.pdf PDF
Draft Solicitation_Special Notice_Charleston CSDC.pdf PDF
25. DRAFT - Template_DHA RMF Security Control Plan_Implementation Guidance.xlsx XLSX spreadsheet
31. DRAFT - Template-Inventory Report-Hardware-Software.pdf PDF
6. DRAFT - JBC CSDC - DP2 FINAL_drawings.pdf PDF
10. DRAFT - JB Charleston CSDC_DOR-Provided Final Furniture-Equipment Package_17Jan22.pdf PDF
22. DRAFT - DHA Privacy Impact Assessment PIA_Processes and Procedures.docx DOCX document
21. DRAFT - DHA MDE Categorization Memo.pdf PDF
11. DRAFT - JSN U0060 Electric Swivel Seated-Narrow-Isle 33' Vertical Swing Reach 3K Fork Lift.pdf PDF
32. DRAFT - Template-Ports-Protocols-Services Management Registry Update.xlsx XLSX spreadsheet
28. DRAFT - Template_Program of Record_DHA Info Sys Contingency Plan.docx DOCX document
2. Real ID TRI-Fold (15Sep20-V42).pdf PDF
27. DRAFT - Template_Information System_Incident Response Plan.docx DOCX document
24. DRAFTExample_IP Network External to Control System_Generic ICS Med-COI Boundary Diagram v4 (1).pdf PDF
18. DRAFT - DHA 27 52 33 Refrigerator Monitoring Systems.pdf PDF
Show all 37

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

Program Office Information System Name Configuration Management Plan Month YYYY

PROGRAM OFFICE INFORMATION SYSTEM NAME

version number

Configuration Management Plan for

[eMASS System Name]

[eMASS SYSTEM ACRONYM]

[System Version 1.5.0.0]

June 2018 Use the month and year of the Authorizing Official (AO) signature in the placeholder above.

Contact Information / Approvals System Owner:

[Enter name]
[Enter date]

Signature and date:

Information System Security Manager:

[Enter name]
[Enter date]

Signature and date:

Information System Security Officer:

[Enter name]
[Enter date]

Signature and date:

Document Revision and History Page

This document will be reviewed at a minimum annually.

DOCUMENT VERSION #
REVISION DATE
DESCRIPTION

OF CHANGE

SECTION/

PARAGRAPH

PAGE

1.0.0
29-June-2015
Original Release
-
-
1.1.0
06-Jan-2016
Added Revision and History Page
Revision and History
i
1.2.0
09-Sep-2016
Administrative updates, review of references, etc.
Global
Global
1.3.0
21-Feb-2017
Administrative updates, review of references, etc.
Global
Global
1.4.0
15-Apr-2017
Administrative updates, review of references, etc.

Revamping of Contingency Planning Controls Table

Re-organization

Addition of CCI tables

Acronym List Updated Global

Pg. 1-2

Global

Global

Pg. 1-2 Global

Pg. 1-2

Global

Global

Pg. 1-2

1.5.0
21 June-2018
Annual Update/ Review

Removal of CCIs that are addressed within the T1 and T2 SOR

Global
Global

Table of Contents

1GENERAL INFORMATION

1CONFIGURATION MANAGEMENT PLAN

1PURPOSE

2SCOPE

2HOW TO USE THIS GUIDE

INTRODUCTION

31.1 Configuration Management Controls

31.2 Scope

41.3 Purpose

51.4 Applicable Provisions and Directives

SYSTEM OVERVIEW

72.1 System Architecture

82.2 Information System Component Inventory [CM-8]

92.3 No Duplicate Accounting of Components [CM-8(5)]

92.4 Automated Unauthorized Component Detection [CM-8(3)]

102.5 Configure Systems, Components, or Devices for High Risk Areas [CM-2(7)]

CONFIGURATION PROGRAM

123.1 Configuration Change Control [CM-3; CM-9]

123.2 Configuration Control Board (CCB)

153.3 Change Request

153.4 Initial Request Evaluation

163.5 CCB Courses of Action

163.6 Unscheduled Changes

163.7 Test Validate and Document Changes [CM-3 (2); CM-9]

173.8 Security Impact Analysis [CM-4]

183.9 Configuration Status Accounting

183.10 Access Restrictions for Change [CM-5; CM-9]

193.11 Configuration Settings [CM-6]

203.12 Configuration Audits

203.13 Least Functionality [CM-7]

213.14 Periodic Review [CM-7(1)]

213.15 Prevent Program Execution [CM-7(2)]

223.16 Unauthorized Software Blacklisting [CM-7(4)]

223.17 Information System Component Inventory [CM-8]

233.18 CM Plan Maintenance

24APPENDIX A: ACRONYM LIST

25APPENDIX B: CCB CHARTER

26APPENDIX C: CHANGE REQUEST FORM TEMPLATE

LisT of Tables 3Table 1-1: Summary of NIST SP 800-53: Configuration Management Plan Controls

15Table 3‑1: Configuration Management Roles and Responsibilities

GENERAL INFORMATION

Configuration Management (CM) is the ongoing process of identifying and managing changes to deliverables and other work products. It is a systems development discipline that promotes the proper identification of the configuration, control of changes, and records the change implementation status of the physical and functional characteristics of an Information Technology (IT) system. Configuration Management identifies what is required, designed, and produced. It also provides for the evaluation of changes including effects on technical and operational performance. This leads to making the configuration visible and understood by all the parties involved with the system.

Configuration management covers three basic essential interdependent activities:

1) Configuration Identification – Configuration identification is for the formal step of identifying the configuration of an item (i.e., name, location, version), and documenting its functional and physical characteristics.

2) Configuration Control – Configuration control is the exercising of established procedures to classify, approve or disapprove, implement, and confirm changes to the agreed upon specifications and baselines.

3) Configuration Management Status Accounting – Configuration accounting is the formal recording and reporting of data relating to configuration identification, approval status of proposed changes, and implementation status of approved changes during all phases of the project.

Configuration Management is therefore the means through which integrity and continuity of the system’s design, and decisions made regarding technical performance, producibility, operability, and supportability are recorded, communicated, and controlled.

CONFIGURATION MANAGEMENT PLAN

A Configuration Management Plan (CMP) is developed to define, document, control, implement, account for, and audit changes to the various components of an IT system. The CMP:

· Provides information on the requirements and procedures necessary for CM activities

· Establishes the methodology for configuration identification and control of releases and changes to configuration items (CI)

· Describes the process for maintaining status accounting and verifying the completeness and correctness of CIs throughout the system lifecycle

A CMP must identify and describe the overall policies and methods for the CM activities to be used during a system’s life cycle.

PURPOSE

This CMP Development Guide provides the framework to identify and describe the overall policies and methods for CM activities to be used during a system’s life cycle. The final CMP product should be delivered in electronically searchable format using an approved documentation presentation. It must be able to stand on its own with all elements explained and acronyms spelled out for reader/reviewers who may not be familiar with the system.

SCOPE

This CMP is a tool used to establish the overall approach for the Configuration Management requirement for the applicable infrastructure system. The CMP will be a dynamic document, and will be updated as work on the system proceeds and the necessity arises.

HOW TO USE THIS GUIDE

The instructions in Sections 1.0 – 3.18 of this document must be adhered to in developing Configuration Management Plans (CMP) for DHA infrastructure systems. This document was developed to ensure that CMPs created using its guidance comply with governing mandates, to include the DHA Risk Management Framework (RMF) requirements.

The structure of the CMP outline provided in Sections 1.0 – 3.18 follows industry standards and best practices for configuration management plans, ensuring the minimum content requirements will be included in the completed artifact. The completed CMP should be structured to allow for discrete sections to cover specific CM activities, all of which are accounted for in the provided CMP outline.

To enhance the utility of the CMP, additional sections/sub-sections may be added, however the content for Sections 1.0 – 3.18 cannot be omitted from the final site CMP. Instructional content is identified by Red text throughout the CMP outline and must be included in the CMP.

1 INTRODUCTION

Example Text: Configuration Management (CM) is the implementation and execution of processes and procedures that ensure the systematic and orderly control of a system and its components throughout its life cycle. CM ensures system integrity by controlling changes to the components of a system.

Configuration Management can be applied at many levels of a system, from subsystem to system and networks of systems. At the system level, configuration management of Department of Defense (DoD) systems requires a focus on secure configurations.

1.1 Configuration Management Controls

The Security Control table identifies controls applicable to Information System (IS) Name ACRONYM.

NOTE: The following Configuration Management Plan controls below are from NIST SP 800-53, Rev. 4. This table will assist you in identifying controls that are applicable to your system. Do not delete any rows in the Table 1-1 below.

If any controls are identified as “Not applicable”, please state “Not applicable” in the section within this document. Do not delete any section within this document.

Delete this notational text box before submitting to DHA CSD for approval.

Control No.
Control Name
Applicability

Select one and delete the other; then change to black font

CM-1
Configuration Management Policy and Procedures
Yes No
CM-2
Baseline Configuration
Yes No
CM-3
Configuration Change Control
Yes No
CM-4
Security Impact Analysis
Yes No
CM-5
Access Restrictions for Change
Yes No
CM-6
Configuration Settings
Yes No
CM-7
Least Functionality
Yes No
CM-9
Configuration Management Plan
Yes No

Table 1-1: Summary of NIST SP 800-53: Configuration Management Plan Controls

1.2 Scope

The Configuration Management Plan describes a tiered approach and organizational framework for implementing and providing oversight of CM processes and controls. Detailed operational processes are to be defined and documented in specific tier level plans, such as CCB Charters.

1.3 Purpose

Configuration Management Policy, Procedures, and Plan [CM-1, CM-9] This Configuration Management Plan (CMP) describes how configuration management will be conducted for the (Program Office/Contractor Name Abbreviation Information System (IS)). This document is intended to be used for the management and control of (Program Office/Contractor Name Abbreviation IS) configurations to enable security and facilitate the management of risk. This CMP is to be used by (Program Office/Contractor Name Abbreviation IS) program personnel as a reference in defining and implementing the operational CM plans and processes by documenting:

1) Formally documented CM roles, responsibilities, and procedures, management commitment, coordination among organizational entities, and compliance

2) A configuration control board that implements procedures to ensure a security review and approval of all proposed DoD information system changes, to include interconnections to other DoD information systems;

3) A testing process that verifies proposed configuration changes prior to implementation in the operational environment ; and

4) A verification process that provides additional assurance that the CM process is working effectively and that the changes outside of the CM process are technically or procedurally not permitted.

CM-1 – Configuration Management Policy And Procedures

CCI
Description
Implementation Procedures

If not applicable, enter the following:

This CCI is not applicable.

CCI-000287
The organization develops and documents a configuration management policy that addresses purpose, scope, roles, responsibilities, management commitment, coordination among organizational entities, and compliance.
CCI-000290
The organization develops and documents procedures to facilitate the implementation of the configuration management policy and associated configuration management controls.
CCI-000292
The organization reviews and updates, on an organization defined frequency, the procedures to facilitate the implementation of the configuration management policy and associated configuration management controls.
CCI-000289
The organization reviews and updates, on an organization defined frequency, the configuration management policy.
CCI-001822
The organization disseminates the configuration management policy to organization defined personnel or roles.
CCI-001825
The organization disseminates to organization defined personnel or roles the procedures to facilitate the implementation of the configuration management policy and associated configuration management controls.

CM-9 – Configuration Management Plan

CCI
Description
Implementation Procedures

If not applicable, enter the following:

This CCI is not applicable.

CCI-000421
The organization develops and documents a configuration management plan for the information system that addresses roles, responsibilities, and configuration management processes and procedures.
CCI-000423
The organization implements a configuration management plan for the information system that addresses roles, responsibilities, and configuration management processes and procedures.

The organization being assessed develops, documents, and annually maintains procedures to facilitate the implementation of the configuration management policy and associated configuration management controls. All updates and review occurrences must be documented.

The organization disseminates a configuration management policy to all stakeholders in the configuration management process to facilitate implementation.

1.4 Applicable Provisions and Directives

Example Text: The CMP is developed in accordance with Federal, Department of Defense (DoD), and Defense Health Agency (DHA) guidance:

STANDARD References:

· DoD Instruction 8500.01, “Cybersecurity”, 14 March 2014

· (DoD) Instruction 8510.01, “Risk Management Framework (RMF) for DoD Information Technology (IT)”, 12 March 2014 Incorporating Change 2, 28 July 2017

· DoDI 8551.01. “Ports Protocols and Services Management” 28 May 2014

· NIST SP 800-53 “Security and Privacy Controls for Federal Information Systems and Organizations”, Rev 4, April 2013

· NIST SP 800-128, "Guide for Security Focused Configuration Management of Information Systems", August 2011

2 SYSTEM OVERVIEW

Provide an overview of the system. Ensure this description is consistent with other Artifacts that contain a system overview description. (Use System description from SP)

2.1 System Architecture

Hardware and Software Baseline [CM-2, CM-2(1), CM-2(3), CM-8, CM-8(1)] The organization documents a current baseline configuration of the information system and maintains updates under configuration control. Baseline Document reviews must be conducted annually, upon any baseline configuration change, component installation, component upgrades, and component removals or as events or circumstances dictate. Previous versions of the baseline configurations of the information system and components are retained for a minimum of 3 months to support rollback.

CM-2 – Baseline Configuration

CCI
Description
Implementation Procedures

If not applicable, enter the following:

This CCI is not applicable.

CCI-00293
The organization develops and documents a current baseline configuration of the information system.
CCI-000295
The organization maintains under configuration control, a current baseline configuration of the information system.

CM-2 (1) – Baseline Configuration | Reviews And Updates

CCI
Description
Implementation Procedures

If not applicable, enter the following:

This CCI is not applicable.

CCI-000296
The organization reviews and updates the baseline configuration of the information system at an organization-defined frequency.
CCI-000297
The organization reviews and updates the baseline configuration of the information system when required due to organization-defined circumstances.
CCI-000298
The organization reviews and updates the baseline configuration of the information system as an integral part of information system component installations.
CCI-000299
The organization reviews and updates the baseline configuration of the information system as an integral part of information system component upgrades.

CM-2(3) – Baseline Configuration | Retention Of Previous Configurations

CCI
Description
Implementation Procedures

If not applicable, enter the following:

This CCI is not applicable.

CCI-000304
The organization retains organization-defined previous versions of baseline configurations of the information system to support rollback.

CM-8 – Information System Component Inventory

CCI
Description
Implementation Procedures

If not applicable, enter the following:

This CCI is not applicable.

CCI-001780
The organization reviews and updates the information system component inventory per organization-defined frequency.

CM-8(1) – Information System Component Inventory | Updates During Installations / Removals

CCI
Description
Implementation Procedures

If not applicable, enter the following:

This CCI is not applicable.

CCI-000408
The organization updates the inventory of information system components as an integral part of component installations.
CCI-000409
The organization updates the inventory of information system components as an integral part of component removals.
CCI-000410
The organization updates the inventory of information system components as an integral part of information system updates.

2.2 Information System Component Inventory [CM-8]

The organization develops and documents an inventory of information system components that includes all components within the authorization boundary of the information system; at a necessary granularity level for tracking and reporting.

A current and comprehensive baseline inventory of all hardware and software (HW/SW) (to include manufacturer, type, model, physical location, network topology or architecture, version, and installation manuals and procedures) is maintained by the CCB as part of the Authorization Package. A backup copy of the inventory is stored in a fire-rated container or otherwise not collocated with the original.

CM-8 – Information System Component Inventory

CCI
Description
Implementation Procedures

If not applicable, enter the following:

This CCI is not applicable.

CCI-000392
The organization develops and documents an inventory of information system components that includes all components within the authorization boundary of the information system.
CCI-000395
The organization develops and documents an inventory of information system components that is at the level of granularity deemed necessary for tracking and reporting.
CCI-000398
The organization defines information deemed necessary to achieve effective information system component accountability.
CCI-000399
The organization develops and documents an inventory of information system components that includes organization defined information deemed necessary to achieve effective information system component accountability.

2.3 No Duplicate Accounting of Components [CM-8(5)]

The organization verifies that all components within the authorization boundary of the information system are not duplicated in other information system inventories.

CM-8(5) – Information System Component Inventory | No Duplicate Accounting Of Components

CCI
Description
Implementation Procedures

If not applicable, enter the following:

This CCI is not applicable.

CCI-000419
The organization verifies that all components within the authorization boundary of the information system are not duplicated in other information system inventories.

2.4 Automated Unauthorized Component Detection [CM-8(3)]

The organization continuously employs automated mechanisms to detect the presence of unauthorized hardware, software, and firmware components within the information system and defines personnel and roles to be notified of such findings.

The organization takes action to disable network access by such components, isolates the components, notifies organization-defined personnel and documents all related activity.

CM-8(3) – Information System Component Inventory | Automated Unauthorized Component Detection

CCI
Description
Implementation Procedures

If not applicable, enter the following:

This CCI is not applicable.

CCI-001783
The organization defines the personnel or roles to be notified when unauthorized hardware, software, and firmware components are detected within the information system.
CCI-001784
When unauthorized hardware, software, and firmware components are detected within the information system, the organization takes action to disable network access by such components, isolates the components, and/or notifies organization-defined personnel or roles.

2.5 Configure Systems, Components, or Devices for High Risk Areas [CM-2(7)] The organization defines and documents, in the configuration management policy, the security configurations to be implemented on information systems, system components, or devices when they are located in areas of significant risk or to individuals traveling to locations the organization deems to be of significant risk.

The organization defines and applies security safeguards to devices when individuals return from areas of significant risk.

CM-2(7) – Baseline Configuration | Configure Systems, Components, Or Devices For High-Risk Areas

CCI
Description
Implementation Procedures

If not applicable, enter the following:

This CCI is not applicable.

CCI-001737
The organization defines the information systems, system components, or devices that are to have organization-defined configurations applied when located in areas of significant risk.
CCI-001738
The organization defines the security configurations to be implemented on information systems, system components, or devices when they are located in areas of significant risk.
CCI-001739
The organization issues organization-defined information systems, system components, or devices with organization-defined configurations to individuals traveling to locations the organization deems to be of significant risk.
CCI-001815
The organization defines the security safeguards to be applied to devices when they return from areas of significant risk.
CCI-001816
The organization applies organization-defined security safeguards to devices when individuals return from areas of significant risk.

3 CONFIGURATION PROGRAM

3.1 Configuration Change Control [CM-3; CM-9]

Configuration control is the process of requesting, evaluating, approving or disapproving proposed changes, and implementing approved changes to the system or subsystem baselines. Configuration control extends throughout the system life cycle.

3.2 Configuration Control Board (CCB)

The Configuration Control Board (CCB) is responsible for maintaining configuration control over Configuration Items (CI’s) in the product baselines. In addition, they are responsible for administering the process by which requests for change to products under control is submitted, reviewed, and approved or disapproved.

The CCB plays an important role as gate keeper in deciding which changes may be acted upon and introduced into an information system. The CCB deliberately considers the potential effect of proposed change on the functionality and secure state of the information system and risk to the mission if the change is implemented or not implemented. By reviewing each proposed and implemented modification, the CCB ensures that there is a disciplined, systematic, and secure approach for introducing change. Having a clearly defined process or framework for the evaluation and approval of change requests (CR), including predefined evaluation criteria, helps to ensure that each proposed and implemented change is evaluated in a consistent and repeatable manner balancing security, business, and technical viewpoints.

The CCB defines within their CCB Charter, the frequency and conditions for configuration change control review and will maintain and review an audit trail of each proposed and decided configuration controlled change.

The CCB determines the types of changes to the information system (configuration items) that are configuration controlled, throughout the system development life cycle and the time period in which records of the changes are retained.

CM-3 – Configuration Change Control

CCI
Description
Implementation Procedures

If not applicable, enter the following:

This CCI is not applicable.

CCI-000314
The organization approves or disapproves configuration controlled changes to the information system with explicit consideration for security impact analysis.
CCI-000318
The organization audits and reviews activities associated with configuration controlled changes to the system.
CCI-000319
The organization coordinates and provides oversight for configuration change control activities through an organization defined configuration change control element (e.g., committee, board) that convenes at the organization defined frequency and/or for any organization defined configuration change conditions.
CCI-000320
The organization defines frequency to convene configuration change control element.
CCI-000321
The organization defines configuration change conditions that prompt the configuration change control element to convene.
CCI-001740
The organization reviews proposed configuration controlled changes to the information system.
CCI-001741
The organization documents configuration change decisions associated with the information system.
CCI-001819
The organization implements approved configuration-controlled changes to the information system.
CCI-000313
The organization determines the types of changes to the information system that are configuration controlled.
CCI-000316
The organization retains records of configuration-controlled changes to the information system for an organization-defined time period.

CM-9 – Configuration Management Plan

CCI
Description
Implementation Procedures

If not applicable, enter the following:

This CCI is not applicable.

CCI-000424
The organization develops and documents a configuration management plan for the information system that defines the configuration items for the information system.
CCI-000426
The organization implements a configuration management plan for the information system that defines the configuration items for the information system.
CCI-001790
The organization develops and documents a configuration management plan for the information system that establishes a process for identifying configuration items throughout the system development life cycle.
CCI-001792
The organization implements a configuration management plan for the information system that establishes a process for identifying configuration items throughout the system development life cycle.
CCI-001796
The organization develops and documents a configuration management plan for the information system that places the configuration items under configuration management.
CCI-001798
The organization implements a configuration management plan for the information system that places the configuration items under configuration management
Role
Responsibility
Subject Matter Expert
· Create a Change Request and forward it to CCB members for review

· Submit additional input and information

· Provide information regarding hardware/software changes and impacts to the system

Information System Security Officer
· Review and evaluate changes to ensure the integrity of the system.

· Review the change process to ensure that the modified configuration maintains its authorization status

· Review and evaluate proposed changes to ensure that the proposed changes are in accordance with DoD security policy and guidance as well as applicable federal laws, directives, policies, regulations, standards, and guidance.

· Notify the AO of significant changes that may impact the IA posture of the system

Information System Security Manager
· Review and evaluate changes to ensure the integrity of the system.

· Review the change process to ensure that the modified configuration maintains its authorization status

· Review and evaluate proposed changes to ensure that the proposed changes are in accordance with DoD security policy and guidance as well as applicable federal laws, directives, policies, regulations, standards, and guidance.

· Notify the ISSO of significant changes that may impact the IA posture of the system

System Owner
· Evaluate proposed changes based on inputs form the CCB and determine action
Project Manager
· Coordinate proposed changes submitted and approved with the technical team

· Assist the CCB members in determining the impact of proposed changes as a subject matter expert where appropriate

Table 3‑1: Configuration Management Roles and Responsibilities

3.3 Change Request

The proposed changes are initiated in a change request (CR). CR’s may be initiated by any member of the program team. A CR documents pertinent information including, the configuration item name, configuration baseline version, requested change, justification for the change, impact of the proposed change, who is requesting the change, etc. Additional information may be gathered by members of the program team or CCB to effectively evaluate the CR. A sample Change Request Form is provided in Appendix (x). CR’s are tracked by a unique ID to ensure accountability, control, traceability to implementation, and auditability.

3.4 Initial Request Evaluation

The evaluation of a change is an important activity of the change request process to validate justification for the change and assess the impact of the proposed change to the system, affected configuration items schedule and budget. The scope and degree of formality for the evaluation process depends on the impact of the change.

The first step is to determine if the change requires configuration control. Some types of changes may be exempt from configuration control or pre-approved as defined by the CCB. If the change is exempt or pre-approved it is noted on the change request and the change is made without further analysis or approval; however, system documentation may still require updating (e.g. the Security Plan, the baseline configuration, component inventory, etc.)

Significant changes may require multiple steps for review, evaluation, and recommendation. Small changes may combine steps to shorten and simplify the process. Best practices for configuration change control require that changes to the information system be vetted by at least one authorized individual who is independent of the requestor.

3.5 CCB Courses of Action

The CCB evaluates each CR. The requestor, technical personnel, or subject matter experts may be called on to explain their position on the request.

For each CR, the CCB has three courses of action:

· Approve. The proposed change is approved and may be scheduled for implementation. The CCB may determine the schedule or leave it to the Technical Manager to implement it when appropriate.

· Deny. The proposed change may not be implemented.

· Defer. The CCB does not make a decision at this point in time. It may determine a time period when it will consider the request again, or leave scheduling for further consideration.

3.6 Unscheduled Changes

Situations may arise that necessitate and unscheduled (emergency) change. It is incumbent upon information system owners to identify all sources of the change to make sure that changes requiring configuration control go through the configuration change control process. Unscheduled changes are reviewed/resolved by the CCB as soon as is practical after unscheduled changes are made.

3.7 Test Validate and Document Changes [CM-3 (2); CM-9]

Once the change has been analyzed and approved, it is tested. A comprehensive set of procedures exist to make sure that it is implemented and test all patches and upgrades prior to deployment.

The organization documents and implements a process to test changes to the information system before implementing the changes on the operational system and maintain an audit trail of testing activity.

The organization documents and validates all changes to the information system before the changes are implemented on the operational system.

The change is then implemented, verified and applicable updates are made to supporting documents, such as technical designs and baseline configurations, the new baseline becomes the current version, and the previous baseline is no longer valid, but is retained for historical purposes. If there are any issues with a production release, retention of previous versions allows for a rollback or restoration to a previous secure and functional version of the baseline configuration. Additionally, archiving previous baseline configurations is useful for incident response and traceability support during formal audits.

CM-3(2) – Configuration Change Control | Test / Validate / Document Changes

CCI
Description
Implementation Procedures

If not applicable, enter the following:

This CCI is not applicable.

CCI-000327
The organization tests changes to the information system before implementing the changes on the operational system.
CCI-000328
The organization validates changes to the information system before implementing the changes on the operational system.
CCI-000329
The organization documents changes to the information system before implementing the changes on the operational system

CM-9 – Configuration Management Plan

CCI
Description
Implementation Procedures

If not applicable, enter the following:

This CCI is not applicable.

CCI-001793
The organization develops and documents a configuration management plan for the information system that establishes a process for managing the configuration of the configuration items.
CCI-001795
The organization implements a configuration management plan for the information system that establishes a process for managing the configuration of the configuration items.

3.8 Security Impact Analysis [CM-4]

It is only when proposed changes are evaluated for their security impact that the configuration change control process yields benefits for the security posture of the information system. A security impact analysis is conducted by individuals or teams within the CCB that possess the technical knowledge of the information system.

The CCB records its analysis of changes to the information system to determine potential security impacts prior to change implementation.

CM-4 – Security Impact Analysis

CCI
Description
Implementation Procedures

If not applicable, enter the following:

This CCI is not applicable.

CCI-000333
The organization analyzes changes to the information system to determine potential security impacts prior to change implementation.

3.9 Configuration Status Accounting

Configuration Status Accounting (CSA) is the recording and reporting of information needed to manage CI’s effectively. CSA includes:

· A record of the approved configuration documentation and identification numbers

· The status of proposed changes, deviations, and waivers to configuration

· The implementation status of approved changes

· The configuration of all units of the CI in the operational inventory

· Results of audits

CSA documentation is the means through which actions affecting CI’s are recorded and reported to interested parties. CM Managers have the primary responsibility for managing, compiling, maintaining, and publishing CSA records and reports. The records and reports provide status information to program management that the changes between the system description and the system itself are being accounted for on a one-to-one relationship. The CM Manager determines the frequency of the distribution and recipients of the CSA reports.

3.10 Access Restrictions for Change [CM-5; CM-9]

The organization defines, documents, approves, and enforces both physical and logical access restrictions associated with changes to the information system.

The organization must document the plan implementations to protect the configuration management plan from unauthorized disclosure and modification, so that all changes to the CM Plan are approved. Measures must include marking, labeling, and handling to prevent improper disclosure.

CM-5 – Access Restrictions for Change

CCI
Description
Implementation Procedures

If not applicable, enter the following:

This CCI is not applicable.

CCI-000338
The organization defines physical access restrictions associated with changes to the information system.
CCI-000339
The organization documents physical access restrictions associated with changes to the information system.
CCI-000340
The organization approves physical access restrictions associated with changes to the information system. The organization enforces physical access restrictions associated with changes to the information system.
CCI-000341
The organization enforces physical access restrictions associated with changes to the information system.
CCI-000342
The organization defines logical access restrictions associated with changes to the information system.
CCI-000343
The organization documents logical access restrictions associated with changes to the information system.
CCI-000344
The organization approves logical access restrictions associated with changes to the information system.
CCI-000345
The organization enforces logical access restrictions associated with changes to the information system.

CM-9 – Configuration Management Plan

CCI
Description
Implementation Procedures

If not applicable, enter the following:

This CCI is not applicable.

CCI-001799
The organization develops a configuration management plan for the information system that protects the configuration management plan from unauthorized disclosure and modification.
CCI-001801
The organization implements a configuration management plan for the information system that protects the configuration management plan from unauthorized disclosure and modification.

3.11 Configuration Settings [CM-6]

The organization documents and implements the use of DoD STIGS for the deployment of acquired IA-enabled products and the establishment of their configuration settings.

The organization identifies, documents, and approves any deviations from the established configuration settings for information system components based on organization-defined operational requirements.

The organization documents, monitors and controls changes to the configuration settings.

CM-6 – Configuration Settings

CCI
Description
Implementation Procedures

If not applicable, enter the following:

This CCI is not applicable.

CCI-000363
The organization defines security configuration checklists to be used to establish and document configuration settings for the information system technology products employed.
CCI-000366
The organization implements the security configuration settings.
CCI-000367
The organization identifies any deviations from the established configuration settings for organization-defined information system components based on organization-defined operational requirements.
CCI-000368
The organization documents any deviations from the established configuration settings for organization-defined information system components based on organization-defined operational requirements.
CCI-000369
The organization approves any deviations from the established configuration settings for organization-defined information system components based on organization-defined operational requirements.
CCI-001756
The organization defines the operational requirements on which the configuration settings for the organization-defined information system components are to be based.
CCI-001502
The organization monitors changes to the configuration settings in accordance with organizational policies and procedures.
CCI-001503
The organization controls changes to the configuration settings in accordance with organizational policies and procedures.

3.12 Configuration Audits

Configuration audits validate that the design and the final product conform to approved functional requirements, as defined in applicable specifications and drawings, and that the changes have been incorporated.

3.13 Least Functionality [CM-7]

The organization is compliant/non-compliant with the DoD defined information system prohibited or restricted functions, ports, protocols, and/or services.

The organization configures the information system to provide only those documented essential capabilities.

CM-7 – Least Functionality

CCI
Description
Implementation Procedures

If not applicable, enter the following:

This CCI is not applicable.

CCI-000381
The organization configures the information system to provide only essential capabilities.
CCI-000382
The organization configures the information system to prohibit or restrict the use of organization-defined functions, ports, protocols, and/or services.

CM-7(1) –Least Functionality | Periodic Review

CCI
Description
Implementation Procedures

If not applicable, enter the following:

This CCI is not applicable.

CCI-001761
The organization defines the functions, ports, protocols and services within the information system that are to be disabled when deemed unnecessary and/or nonsecure.
CCI-001762
The organization disables organization-defined functions, ports, protocols, and services within the information system deemed to be unnecessary and/or nonsecure.

3.14 Periodic Review [CM-7(1)]

The organization documents and implements a process to review the information system every 30 days to identify unnecessary and non-secure functions, ports, protocols, and services.

CM-7(1) –Least Functionality | Periodic Review

CCI
Description
Implementation Procedures

If not applicable, enter the following:

This CCI is not applicable.

CCI-000384
The organization reviews the information system per organization defined frequency to identify unnecessary and nonsecure functions, ports, protocols, and services.

3.15 Prevent Program Execution [CM-7(2)]

The organization documents its compliance with DoDI 8551 and only allows DoD approved network capable software programs to be used within the information system.

The organization configures the information system to prevent the execution of programs not authorized in accordance with DoDI 8551.

CM-7(2) –Least Functionality | Prevent Program Execution

CCI
Description
Implementation Procedures

If not applicable, enter the following:

This CCI is not applicable.

CCI-001592
The organization defines the rules authorizing the terms and conditions of software program usage on the information system.
CCI-001763
The organization defines the policies regarding software program usage and restrictions
CCI-001764
The information system prevents program execution in accordance with organization-defined policies regarding software program usage and restrictions, and/or rules authorizing the terms and conditions of software program usage.

3.16 Unauthorized Software Blacklisting [CM-7(4)]

The organization defines and identifies the software programs not authorized to execute on the information system; and documents a review of the identified list on a monthly basis.

CM-7(4) –Least Functionality | Unauthorized Software Blacklisting

CCI
Description
Implementation Procedures

If not applicable, enter the following:

This CCI is not applicable.

CCI-001765
The organization defines the software programs not authorized to execute on the information system.
CCI-001766
The organization identifies the organization-defined software programs not authorized to execute on the information system.
CCI-001767
The organization employs an allow-all, deny-by-exception policy to prohibit the execution of unauthorized software programs on the information system.
CCI-001770
The organization reviews and updates the list of unauthorized software programs per organization-defined frequency.

3.17 Information System Component Inventory [CM-8]

The organization develops and documents an inventory of information system components that includes all components within the authorization boundary of the information system; at a necessary granularity level for tracking and reporting.

CM-8 –Information System Component Inventory

CCI
Description
Implementation Procedures

If not applicable, enter the following:

This CCI is not applicable.

CCI-000392
The organization develops and documents an inventory of information system components that includes all components within the authorization boundary of the information system.
CCI-000395
The organization develops and documents an inventory of information system components that is at the level of granularity deemed necessary for tracking and reporting.

3.18 CM Plan Maintenance

Configuration Mangers review configuration management policies and processes, at least annually, to ensure that all CM processes are up to date and comply with pertinent DoD policies. All changes will be incorporated as a document revision. Updates to this document are recorded on the Version History section of this document.

APPENDIX A: ACRONYM LIST

Acronyms used specifically in this Artifact are to be listed in this appendix.

ACRONYM
TERM
AIS
Automated Information System
CCB
Configuration Control Board
CCI
Control Correlation Identifier
CI
Configuration Item

CM

Configuration Management

CMP
Configuration Management Plan
CR
Change Request
CSA
Configuration Status Accounting
DHA
Defense Health Agency
DoD
Department of Defense
HW/SW
Hardware/Software
IA
Information Assurance

IS

Information System

ISSM
Information System Security Manager
ISSO
Information System Security Officer
IT
Information Technology
NIST
National Institute of Standards and Technology
STIGS
Security Technical Implementation Guides

APPENDIX B: CCB CHARTER

INSERT YOUR CCB CHARTER HERE

APPENDIX C: CHANGE REQUEST FORM TEMPLATE

The following is a sample template for a Configuration Management Change Request artifact that can be used within a SecCM program. Organizations are encouraged to adapt it to suit their needs. Please be as concise as possible.

CONFIGURATION CHANGE REQUEST FORM

Date Prepared: MMM/DD/YYYY Title of Change Request:

Change Initiator/Project Manager:

Change Description:

Change Justification:

Urgency of Change: Scheduled/Urgent/Unscheduled IS Components/CIs to be Changed:

Other IS Components, CIs, or Systems to Be Affected by Change:

Personnel involved with the Change:

Expected Security Impact of Change:

Expected Functional Impact of Change:

Expected Impact of Not Doing Change:

Potential Interface/Integration Issues:

Required Changes to Existing Applications:

Project work plan including change implementation date, deliverables, and back-out plan:

Funding Required to Implement Change:

The Configuration Management Change Request has been Approved/Disapproved. The CM Change Request has been rejected due to enter justification.

Authorized Signature(s):

Title:

Date:

Add appropriate classification marking

FOR OFFICIAL USE ONLY

File details come from the government source that posted it. Updated .