Skip to content

CM-9: Configuration Management Plan

An OSCAL Control

Statement

    • Develop, document, and implement a configuration management plan for the system that:

      • a.

        Addresses roles, responsibilities, and configuration management processes and procedures;

      • b.

        Establishes a process for identifying configuration items throughout the system development life cycle and for managing the configuration of the configuration items;

      • c.

        Defines the configuration items for the system and places the configuration items under configuration management;

      • d.

        Is reviewed and approved by ; and

      • e.

        Protects the configuration management plan from unauthorized disclosure and modification.

      • Guidance:

        FedRAMP does not provide a template for the Configuration Management Plan. However, NIST SP 800-128, Guide for Security-Focused Configuration Management of Information Systems, provides guidelines for the implementation of CM controls as well as a sample CMP outline in Appendix D of the Guide