CM-1
Configuration Management
Policy and Procedures
Description
a. Develop, document, and disseminate to [organization-defined parameter]: b. Designate an [organization-defined parameter] to manage the development, documentation, and dissemination of the configuration management policy and procedures; and c. Review and update the current configuration management:
Mapped SPARTA techniques
No techniques mapped to this control.
Cross-framework references
Relationships published by the source frameworks themselves, reproduced here with attribution. They are not SafeMode Space mappings and carry no confidence rating of ours.
Referenced by 9 in NIST Cybersecurity Framework 2.0
- GV.OC-03Legal, regulatory, and contractual requirements regarding cybersecurity - including privacy and civil liberties obligations - are understood and managed
- GV.OV-01Cybersecurity risk management strategy outcomes are reviewed to inform and adjust strategy and direction
- GV.PO-01Policy for managing cybersecurity risks is established based on organizational context, cybersecurity strategy, and priorities and is communicated and enforced
- GV.PO-02Policy for managing cybersecurity risks is reviewed, updated, communicated, and enforced to reflect changes in requirements, threats, technology, and organizational mission
- GV.SC-03Cybersecurity supply chain risk management is integrated into cybersecurity and enterprise risk management, risk assessment, and improvement processes
- ID.IM-01Improvements are identified from evaluations
- ID.IM-02Improvements are identified from security tests and exercises, including those done in coordination with suppliers and relevant third parties
- ID.IM-03Improvements are identified from execution of operational processes, procedures, and activities
- PR.PS-01Configuration management practices are established and applied
Cite as SafeMode Space, nist-80053-rev5 CM-1.