FedRAMP Controls / CM

CM-2(3) Retention of Previous Configurations

Family CM
Baselines moderate
Mapped KSIs 2

Control statement

Retain {{ insert: param, cm-02.03_odp }} of previous versions of baseline configurations of the system to support rollback.

Parameter placeholders {{ insert: param, … }} reference FedRAMP-set values in the resolved profile. Full parameter map is preserved in the catalog database.

Covered by these Key Security Indicators

KSITitleCategory
KSI-RPL-03System Backups
_Persistently_ review the alignment of machine-based information resource backups with defined recovery objectives.
Recovery Planning
KSI-SVC-04Configuration Automation
Manage configuration of machine-based information resources using automation.
Service Configuration