Require [Assignment: organization-defined security and privacy representatives] to be members of the [Assignment: organization-defined configuration change control element].
| ID | Name | Description | D3FEND | |
| ID | Description | |
| Requirement | Rationale/Additional Guidance/Notes |
|---|---|
| The [organization] shall ensure security representatives are included in all change control board reviews and decisions.{CM-3(4),SA-10(7)} |
| ID | Name | Description | |
|---|---|---|---|