id: "CM-04(02)" title: "Verification of Controls" family: "CM" family_name: "Configuration Management" sort_id: "cm-04.02" priority: "P1" implementation_level: "organization" parent: "CM-04" enhancement: True
Statement
After system changes, verify that the impacted controls are implemented correctly, operating as intended, and producing the desired outcome with regard to meeting the security and privacy requirements for the system.
Guidance
Implementation in this context refers to installing changed code in the operational system that may have an impact on security or privacy controls.
Assessment Objective: the impacted controls are implemented correctly with regard to meeting the security requirements for the system after system changes;
Assessment Objective: the impacted controls are implemented correctly with regard to meeting the privacy requirements for the system after system changes;
Assessment Objective: the impacted controls are operating as intended with regard to meeting the security requirements for the system after system changes;
Assessment Objective: the impacted controls are operating as intended with regard to meeting the privacy requirements for the system after system changes;
Assessment Objective: the impacted controls are producing the desired outcome with regard to meeting the security requirements for the system after system changes;
Assessment Objective: the impacted controls are producing the desired outcome with regard to meeting the privacy requirements for the system after system changes.
Configuration management policy
procedures addressing security impact analyses for changes to the system
procedures addressing privacy impact analyses for changes to the system
privacy risk assessment documentation
configuration management plan
security and privacy impact analysis documentation
privacy impact assessment
analysis tools and associated outputs
change control records
control assessment results
system audit records
system component inventory
system security plan
privacy plan
other relevant documents or records
Organizational personnel with responsibility for conducting security and privacy impact analyses
organizational personnel with information security and privacy responsibilities
system/network administrators
security and privacy assessors
Organizational processes for security and privacy impact analyses
mechanisms supporting and/or implementing security and privacy impact analyses of changes