FedRAMP Controls / CM

CM-3(2) Testing, Validation, and Documentation of Changes

Family CM
Baselines moderate
Mapped KSIs 3

Control statement

Test, validate, and document changes to the system before finalizing the implementation of the changes.

Parameter placeholders {{ insert: param, … }} reference FedRAMP-set values in the resolved profile. Full parameter map is preserved in the catalog database.

Covered by these Key Security Indicators

KSITitleCategory
KSI-CMT-01Log and Monitor Changes
Log and monitor modifications to the cloud service offering.
Change Management
KSI-CMT-03Automated Testing and Validation
Automate persistent testing and validation of changes throughout deployment.
Change Management
KSI-CMT-04Change Management Procedures
_Persistently_ review the effectiveness of documented change management procedures.
Change Management