Require [Assignment: organization-defined security and privacy representatives] to be members of the [Assignment: organization-defined configuration change control element].
ID | Name | Description | D3FEND |
ID | Description |
Requirement | Rationale/Additional Guidance/Notes |
---|---|
The [organization] shall ensure security representatives are included in all change control board reviews and decisions.{CM-3(4),SA-10(7)} |
ID | Name | Description |
---|