Nist Configuration Management Plan Template
Information technology laboratory itl national vulnerability database nvd announcement and discussion lists general questions webmaster contact emailnvd at nistgov incident response assistance and non nvd related technical cyber security questions.
Nist configuration management plan template. The new guide nist sp 800 128 supports the implementation of the configuration management family of security controls that are defined in nist sp 800 53. Organizations can employ templates to help ensure consistent and timely development and implementation of configuration management plans. Nist sp 800 128 assumes that information security is an integral part of an organizations overall configuration management. Insert company name information system security plan.
Information system owner date. The focus of this document is on implementation of the information system security aspects of configuration management and as such the term security focused configuration management seccm is used to emphasize the concentration on information security. National institute of standards and technology 17. Configuration management cm is the ongoing process of identifying and managing changes to deliverables and other work products.
Fisma also directs federal agencies to apply a risk based policy to achieve cost effective results for the security of their information systems. Review and approvals. The cmp provides information on the requirements and. Areas in italics or highlighted must be completed.
Such templates can represent a master configuration management plan for the organization at large with subsets of the plan implemented on a system by system basis. Configuration management concepts and principles described in nist sp 800 128 provide supporting information for nist sp 800 53 recommended security controls for federal information systems and organizations. Department of defense computer aided acquisition and logistics support cals program. Information system security plan template.
The national pdes testbed was established at the national institute of standards and technology nist in 1988 under the sponsorship of the us. Configuration and change management presents an overview of the configuration and change management process and establishes some basic terminology. 1 scap security content automation protocol the primary purpose of scap is to improve the automated application verification and reporting of commercial information technology product specific security configuration settings. Create a configuration and change management plandetails the process of creating a configuration and change management plan and identifies details that an organization should consider when developing its plan.
The configuration management plan cmp is developed to define document control implement account for and audit changes to the various components of this project. An integral part of an organizations overall configuration management.