December 2021
Beginner
550 pages
20h 48m
English
It is common to discuss change and configuration control as a pair of activities, but they are really two ends of a spectrum. The confusion lies in where a particular activity crosses from one to another. Drawing a sharp line between the two is difficult because organizations of different complexities will draw the line in different places:
Configuration control is the management of the baseline settings for a system device so that it meets security requirements. The settings must be implemented carefully and only with prior approval.
Change control is the management of changes to the configuration. Unmanaged changes introduce risk because they might affect security operations or controls, and an improper change ...