Policy Advisory

Policy Advisory  Change and Configuration Management Policy

Date: 01/01/2025
Organization: Cybersecurity and Enterprise Risk Management
Referenced Sources: MGL Chapter 7D, Section 2

The Change and Configuration Management Policy reinforces the Commonwealth’s commitment to an effective change and configuration management program and outlines the controls necessary to safeguard the Commonwealth’s information assets and reduce risks posed by improper change and configuration management practices.

Contact   for Change and Configuration Management Policy

Cybersecurity and Enterprise Risk Management

Online

For cybersecurity or risk management questions: Email Cybersecurity and Enterprise Risk Management at ERM@mass.gov

Table of Contents

Purpose

The purpose of this policy is to establish the minimum security requirements and key information security considerations that Commonwealth Agencies and Offices must implement as part of the following programs:

• Operations Management 

• Change and Configuration Management 

• Release Management 

• Data Backup and Restoration 

• Cloud Computing 

Downloads   for Change and Configuration Management Policy

Contact   for Change and Configuration Management Policy

Online

For cybersecurity or risk management questions: Email Cybersecurity and Enterprise Risk Management at ERM@mass.gov
Referenced Sources:

Help Us Improve Mass.gov  with your feedback

Please do not include personal or contact information.
Feedback