|
controlCM-9
Configuration Management Plan (CM-9)
Develop, document, and implement a configuration management plan for the system that:
Security Baselines
MODERATEHIGHLOW
configurationbaselineschange-control
Why These Connect
Maps To5
These are equivalent or closely aligned requirements in other frameworks.
Baselined In2
This control is included in the linked security baseline (LOW, MODERATE, or HIGH).
Supports14
These related controls work together — a change to one may affect the others.
Enhances1
These enhancements add specific capabilities or refinements to the base control.
Related Controls(9)
CM-2Baseline Configuration (CM-2)
LMH
CM-3Configuration Change Control (CM-3)MH
CM-4Impact Analyses (CM-4)LMH
CM-5Access Restrictions for Change (CM-5)LMH
CM-8System Component Inventory (CM-8)LMH
PL-2System Security and Privacy Plans (PL-2)LMH
RA-8Privacy Impact Assessments (RA-8)SA-10Developer Configuration Management (SA-10)MH
SI-12Information Management and Retention (SI-12)LMH
Cross-Framework Mappings(5)
ID.AM-08ID.AM-08Final
NIST OLIR informative reference — Cybersecurity Framework v2.0 to SP 800-53 Rev 5
PR.PS-01PR.PS-01Final
NIST OLIR informative reference — Cybersecurity Framework v2.0 to SP 800-53 Rev 5
ISO 27001ISO/IEC 27001:20222 mappingsFinal
NIST OLIR informative reference — SP 800-53 Rev 5 to ISO/IEC 27001:2022
ID.AM-08ID.AM-08Final
NIST OLIR informative reference — Cybersecurity Framework v2.0 to SP 800-53 Rev 5
PR.PS-01PR.PS-01Final
NIST OLIR informative reference — Cybersecurity Framework v2.0 to SP 800-53 Rev 5