SA-10 Developer Configuration Management
Last Review: 10/1/22
Statement
WTAMU requires that developers of information system services, both internal and external, perform proper configuration management and consider the impact on information security of any changes or enhancements.
Applicability
This Control applies to all West Texas A&M information resources. The intended audience for this Control includes all information resource developers, owners, and custodians of information resources.
Implementation
The developers of information systems, or components shall do the following:
- Perform configuration management during design, development, implementation, or operation;
- Document, manage, and control the integrity of changes;
- Implement only university or unit-approved changes;
- Document approved changes and the potential security impacts of such changes
- Track security flaws and flaw resolution and report findings to information owner or information security officer.