FedRAMP Controls / CM
CM-3(2) Testing, Validation, and Documentation of Changes
Family CM
Baselines moderate
Mapped KSIs 3
Control statement
Test, validate, and document changes to the system before finalizing the implementation of the changes.
Parameter placeholders {{ insert: param, … }} reference FedRAMP-set values in the resolved profile. Full parameter map is
preserved in the catalog database.
Covered by these Key Security Indicators
| KSI | Title | Category |
|---|---|---|
| KSI-CMT-01 | Log and Monitor Changes Log and monitor modifications to the cloud service offering. | Change Management |
| KSI-CMT-03 | Automated Testing and Validation Automate persistent testing and validation of changes throughout deployment. | Change Management |
| KSI-CMT-04 | Change Management Procedures _Persistently_ review the effectiveness of documented change management procedures. | Change Management |