HomeControl Library › 3.4.3
3.4 Configuration Management1 ptPOA&M-eligible

3.4.3 — Control and log changes

Track, review, approve or disapprove, and log changes to organizational systems.

Changes to systems are tracked, reviewed, approved, and logged.

What it actually means

A basic change-management process: proposed changes are tracked, reviewed, approved (or rejected), and the decision is logged. It keeps ad-hoc changes from quietly breaking your security posture.

Pass or fail — an assessor needs a "yes" to each

What to have ready

Where teams trip up

See where this control puts your score

Run all 110 requirements free in about 10 minutes.

Calculate your SPRS score →

Connected requirements

← Back to the Control Library