Skip to main content
CHG

Change Management

19 controls

Manage change in a sustainable and ongoing manner that involves active participation from both technology and business stakeholders to ensure that only authorized changes occur.

SCF # Control Name Weight NIST CSF Frameworks
CHG-01 Change Management Program 10 — Critical Protect 96
CHG-02 Configuration Change Control 8 — High Protect 84
CHG-02.1 Prohibition Of Changes 10 — Critical Protect 43
CHG-02.2 Test, Validate & Document Changes 9 — Critical Protect 61
CHG-02.3 Cybersecurity & Data Protection Representative for Asset Lifecycle Changes 7 — High Protect 34
CHG-02.4 Automated Security Response 5 — Medium Protect 8
CHG-02.5 Cryptographic Management 5 — Medium Protect 9
CHG-03 Security Impact Analysis for Changes 9 — Critical Protect 74
CHG-04 Access Restriction For Change 8 — High Protect 59
CHG-04.1 Automated Access Enforcement / Auditing 3 — Low Detect 27
CHG-04.2 Signed Components 3 — Low Protect 18
CHG-04.3 Dual Authorization for Change 6 — Medium Protect 29
CHG-04.4 Permissions To Implement Changes 6 — Medium Protect 29
CHG-04.5 Library Privileges 8 — High Protect 11
CHG-05 Stakeholder Notification of Changes 9 — Critical Protect 34
CHG-06 Control Functionality Verification 9 — Critical Protect 41
CHG-06.1 Report Verification Results 5 — Medium Identify 7
CHG-07 Emergency Changes 9 — Critical Protect 2
CHG-07.1 Documenting Emergency Changes 7 — High Protect 2

The Secure Controls Framework (SCF) is maintained by SCF Council. Use of SCF content is subject to the SCF Terms & Conditions.

Manage SCF Controls in SCF Connect

Streamline your compliance program with automated control tracking, evidence management, and framework mapping.