Revision Control and Configuration Management

As a followup to testing and acceptance policies in the previous sections, one way to ensure the ability to uninstall versions of software is through revision control or configuration management. The security impact of change management is knowing the configuration of the system and its components. By knowing what is supposed to be in the system and the network, the administrators can tell if security has been violated and rogue programs have been installed on the system.

Some aspects of configuration management duplicate the policies that were discussed for software development. However, not everything under this system will be from software development. They are included here to amplify their ...

Get Writing Information Security Policies now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.