Skip to main content

SID-OPS-05 — Secure Configuration Management

PropertyValue
Ownerplatform
Categoryprocess
CSF Functiongovern
GroupOperational Controls

Description

Formal secure configuration management process with materiality assessment. Deployment-time configuration changes are classified by impact and risk. Notification to certification body for material changes. Staged deployment process with rollback procedures.

Operator Responsibility

Implement secure configuration management for deployment-specific configuration, infrastructure changes, versioning, approval, rollback, and notification to certification body.

Framework Requirements

EUDI Security Requirements: WIN-8.4.3-Sec-02, CS-I.2-Change, CS-I.3-Load

ISO 27001 Annex A: A.8.9, A.8.19, A.8.32

STRIDE Threat Model: SP-T-1, SP-R-1