CM-3(4) - Configuration Change Control | Security and Privacy Representatives
Require [Assignment: organization-defined security and privacy representatives] to be members of the [Assignment: organization-defined configuration change control element].
Separation of duties in change approval processes reduces the risk of a single insider making unauthorized modifications. For instance, one engineer might propose a new flight software patch. At the same time, another official, often from mission assurance, must validate and sign off on its security impact before it is packaged for upload. This layered approval chain is crucial in high-stakes environments like space, where unintended changes can lead to mission loss or system compromise. By ensuring no single individual can develop and approve a change unilaterally, the organization significantly lowers the chance of malicious code slipping past review gates.