id: "CM-04(02)" title: "Verification of Controls" family: "CM" family_name: "Configuration Management" sort_id: "cm-04.02" priority: "P1" implementation_level: "organization" parent: "CM-04" enhancement: True


Statement

After system changes, verify that the impacted controls are implemented correctly, operating as intended, and producing the desired outcome with regard to meeting the security and privacy requirements for the system.

Guidance

Implementation in this context refers to installing changed code in the operational system that may have an impact on security or privacy controls.

Assessment Objective: the impacted controls are implemented correctly with regard to meeting the security requirements for the system after system changes;

Assessment Objective: the impacted controls are implemented correctly with regard to meeting the privacy requirements for the system after system changes;

Assessment Objective: the impacted controls are operating as intended with regard to meeting the security requirements for the system after system changes;

Assessment Objective: the impacted controls are operating as intended with regard to meeting the privacy requirements for the system after system changes;

Assessment Objective: the impacted controls are producing the desired outcome with regard to meeting the security requirements for the system after system changes;

Assessment Objective: the impacted controls are producing the desired outcome with regard to meeting the privacy requirements for the system after system changes.

Configuration management policy

procedures addressing security impact analyses for changes to the system

procedures addressing privacy impact analyses for changes to the system

privacy risk assessment documentation

configuration management plan

security and privacy impact analysis documentation

privacy impact assessment

analysis tools and associated outputs

change control records

control assessment results

system audit records

system component inventory

system security plan

privacy plan

other relevant documents or records

Organizational personnel with responsibility for conducting security and privacy impact analyses

organizational personnel with information security and privacy responsibilities

system/network administrators

security and privacy assessors

Organizational processes for security and privacy impact analyses

mechanisms supporting and/or implementing security and privacy impact analyses of changes