risk

Absent or weak change-control procedures

Changes to systems, software, hardware, or configurations without formal approval and testing (including unauthorized or poorly tested hardware/config changes) introduce new vulnerabilities, instability, or failed releases.

Record JSON · Open in map · Data retrieval guide

Catalog revision: f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e. A connection does not establish full coverage.

Attributes

category
cyber_security
domain
  • Secure Configuration & Change Management
  • Secure Development (SDLC) & Application Security
taxonomy
  • iso-27005-vulnerability
inherent_rating
medium

Details

risk_id
config-weak-change-control
category
cyber_security
likelihood
medium
impact
medium
inherent_rating
medium
treatment
mitigate
taxonomies
  • iso-27005-vulnerability

Source

No record-specific source URL is provided.

Connections