graphgrc

SCF - CFG-02.7 - Approved Configuration Deviations

Mechanisms exist to document, assess risk and approve or deny deviations to standardized configurations.

Mapped framework controls

NIST 800-53

Control questions

Does the organization document, assess risk and approve or deny deviations to standardized configurations?