This objective requires your organization to define which types of configuration changes must be authorized before being implemented, especially on systems that handle Controlled Unclassified Information (CUI).
This objective requires your organization to define which types of configuration changes must be authorized before being implemented, especially on systems that handle Controlled Unclassified Information (CUI).