CMMC v2.11 Practices

CM.L2-3.4.4  

Reference: CMMC v2.11

Family: CM

Level Introduced: 2

Title: Security Impact Analysis

Practice:
Analyze the security impact of changes prior to implementation.

Further Discussion:
Changes to complex environments are reviewed for potential security impact before implemented. Changes to IT systems can cause unforeseen problems and have unintended consequences for both users and the security of the operating environment. Analyze the security impact of changes prior to implementing them. This can uncover and mitigate potential problems before they occur.

Example
You have been asked to deploy a new web browser plug-in. Your standard change management process requires that you produce a detailed plan for the change, including a review of its potential security impact. A subject-matter expert who did not submit the change reviews the plan and tests the new plug-in for functionality and security. You update the change plan based on the expert’s findings and submit it to the change control board for final approval [a].

Potential Assessment Considerations
• Are configuration changes tested, validated, and documented before installing them on the operational system [a]?

This is for registered users only. Please sign up for a free account, or Login, to see complete cross references to other standards and frameworks.

This is for registered users only. Please sign up for a free account, or Login, to see complete cross references to other standards and frameworks.

Source: CMMC v2.11