Which control governs when and how configuration changes are made to information systems?

Prepare for the FISMA Interview Test. Get familiar with key topics and enhance your knowledge with flashcards and multiple-choice questions. Study effectively and be ready for your exam!

Multiple Choice

Which control governs when and how configuration changes are made to information systems?

Explanation:
Governing when and how changes are made to information systems is handled by configuration change control, a specific practice within configuration management. This control formalizes the process for initiating, reviewing, approving, testing, and implementing changes, as well as documenting outcomes and maintaining a reliable change history. By requiring change requests to be assessed for impact, authorized before implementation, tested in a controlled environment, and properly recorded, it ensures changes are deliberate, traceable, and do not disrupt operations or introduce new risks. Other controls focus on different areas: vulnerability scanning targets finding security weaknesses, security categorization (FIPS 199) classifies the potential impact of a breach, and system interconnections (CA-3) governs how systems connect with others. None of these govern the process of approving and enacting configuration changes.

Governing when and how changes are made to information systems is handled by configuration change control, a specific practice within configuration management. This control formalizes the process for initiating, reviewing, approving, testing, and implementing changes, as well as documenting outcomes and maintaining a reliable change history. By requiring change requests to be assessed for impact, authorized before implementation, tested in a controlled environment, and properly recorded, it ensures changes are deliberate, traceable, and do not disrupt operations or introduce new risks.

Other controls focus on different areas: vulnerability scanning targets finding security weaknesses, security categorization (FIPS 199) classifies the potential impact of a breach, and system interconnections (CA-3) governs how systems connect with others. None of these govern the process of approving and enacting configuration changes.

Subscribe

Get the latest from Passetra

You can unsubscribe at any time. Read our privacy policy