NIST 800-171 v2
110 security requirements available
Configuration Management
Security Requirement
Analyze the security impact of changes prior to implementation.
Discussion
Organizational personnel with information security responsibilities (e.g., system administrators, system security officers, system security managers, and systems security engineers) conduct security impact analyses. Individuals conducting security impact analyses possess the necessary skills and technical expertise to analyze the changes to systems and the associated security ramifications. Security impact analysis may include reviewing security plans to understand security requirements and reviewing system design documentation to understand the implementation of controls and how specific changes might affect the controls. Security impact analyses may also include risk assessments to better understand the impact of the changes and to determine if additional controls are required. [SP 800-128] provides guidance on configuration change control and security impact analysis.
- Framework
- NIST SP 800-171 Rev 2
- Family
- Configuration Management
- Requirement Type
- derived
Related Frameworks
4 paths across 3 frameworks
Related Frameworks
SCF1 mapping
- NIST · Rev 2 (Feb 2020, errata Jan 2021) · nist_800_171_app_d · equivalent
- Secure Controls Framework · 2026.2 · scf_strm · equivalent
NIST 800-531 mapping
- NIST · Rev 2 (Feb 2020, errata Jan 2021) · nist_800_171_app_d · equivalent
CCI2 mappings
- NIST · Rev 2 (Feb 2020, errata Jan 2021) · nist_800_171_app_d · equivalent
- DISA · 2025-01-23 · disa_cci_list · equivalent
- NIST · Rev 2 (Feb 2020, errata Jan 2021) · nist_800_171_app_d · equivalent
- DISA · 2025-01-23 · disa_cci_list · equivalent
Related STIGs
21 STIGs reach this control through 11 CCIs via 800-53 control CM-4. Expand a row to see the responsible NICE and O*NET roles.