CM-3(4)_security-and-privacy-representatives
Require [organization-defined] to be members of the [organization-defined].
Browse reusable Agent Skills, each with a clear purpose and practical guidance.
Require [organization-defined] to be members of the [organization-defined].
Ensure that cryptographic mechanisms used to provide the following controls are under configuration management: [organization-defined].
Determine and document the types of changes to the system that are configuration-controlled;
Analyze changes to the system in a separate test environment before implementation in an operational environment, looking for security and privacy imp
Analyze changes to the system to determine potential security and privacy impacts prior to change implementation.
Enforce access restrictions using [organization-defined] ;
Enforce dual authorization for implementing changes to [organization-defined].
Limit privileges to change system components and system-related information within a production or operational environment;
Limit privileges to change software resident within software libraries.