官术网_书友最值得收藏!

Configuration management policy

The configuration management policy establishes rules to ensure that changes to the information system are minimally disruptive to the functioning of the information system and the users that it supports. The configuration management policy also establishes rules that require IT professionals to document and track changes to an information system.

What the configuration management policy should address:

  • Establishing and maintaining baseline configurations and inventories of organizational information systems (including hardware, software, firmware, and documentation) throughout the respective system development life cycles
  • Establishing and enforcing security configuration settings for information technology products employed in organizational information systems
  • Tracking, reviewing, approving/disapproving, and auditing changes to information systems
  • Analyzing the security impact of changes prior to implementation
  • Defining, documenting, approving, and enforcing physical and logical access restrictions associated with changes to the information system
  • Employing the principle of least functionality by configuring the information system to provide only essential capabilities
  • Restricting, disabling, and preventing the use of non-essential programs, functions, ports, protocols, and services
  • Applying deny-by-exception (blacklisting) policies to prevent the use of unauthorized software or deny all, permit-by-exception (whitelisting) policies, to allow the execution of authorized software
  • Controlling and monitoring user-installed software
主站蜘蛛池模板: 外汇| 获嘉县| 灵石县| 都匀市| 旌德县| 新民市| 广宁县| 兴业县| 安福县| 牟定县| 沛县| 盐津县| 阳江市| 许昌市| 来凤县| 寿宁县| 镇巴县| 米易县| 松阳县| 达日县| 娱乐| 肃北| 象州县| 五华县| 秭归县| 札达县| 获嘉县| 湖口县| 镇远县| 陈巴尔虎旗| 丰顺县| 揭东县| 壶关县| 富顺县| 永定县| 阳新县| 太湖县| 偃师市| 桑日县| 河北区| 太原市|