Changes to systems are tracked, reviewed, approved, and logged.
What it actually means
A basic change-management process: proposed changes are tracked, reviewed, approved (or rejected), and the decision is logged. It keeps ad-hoc changes from quietly breaking your security posture.
Pass or fail — an assessor needs a "yes" to each
- Changes are tracked and approved before implementation.
- Approval/disapproval is logged.
- A defined process exists (even a lightweight ticket/log).
What to have ready
- Change-management policy
- Change tickets/records with approvals
Where teams trip up
- Changes made directly with no record
- No approval step for production changes
See where this control puts your score
Run all 110 requirements free in about 10 minutes — or draft your SSP language for this control. No signup.
Calculate your SPRS score →Draft your SSP language →Connected requirements
More in Configuration Management (3.4)
3.4.1 — Inventory and baseline your systems3.4.2 — Enforce secure configuration settings3.4.4 — Check changes before you make them3.4.5 — Restrict who can make changes3.4.6 — Least functionality3.4.7 — Block nonessential ports and services3.4.8 — Control which software can run3.4.9 — Control user-installed software