CM-5 Access Restrictions for Change
Last Review: 10/1/22
Statement
West Texas A&M University must implement controls to ensure changes to information systems are properly authorized and managed prior to change implementation.
Applicability
This control applies to all West Texas A&M network information resources. The intended audience for this control includes all information resource owners, custodians, and users of information resources.
Implementation
To properly manage changes to information systems the ISO shall work with system owners or custodians to implement and document proper restrictions to ensure only authorize personnel are able to implement changes to information systems. This may include either physical or logical access controls depending on the capabilities of the system.