🚨 CMMC Phase One started November 10! Here's everything you need to know →

Requirement:

Cybersecurity requirements must be included in project and asset (information/technology) change management methodology and procedures to identify and manage cybersecurity risks as part of project management lifecycle. The cybersecurity requirements must be a key part of the overall requirements of technology projects.

Control Implementation Guidelines:

  • Include cybersecurity requirements in the project management methodology and procedures and in the change management of the information and technology assets in the organization to ensure that cybersecurity risks are identified and addressed. Such requirements include:
  • 1
    • Assess and detect vulnerabilities before the deployment of services or systems online, or upon any change to systems within Information and Technology Project Management
    • Fix identified vulnerabilities before launching projects and changes
    • Review Secure Configuration and Hardening and Patching and address observations identified before launching projects and changes
    • Define the requirements for connection with cyber surveillance systems
  • Support cybersecurity requirements of the project management methodology and procedures by the Executive Management through the approval of the head of the organization or his/her deputy

Relevant Cybersecurity Tools:

  • Secure Software Development Cycle Policy Template
  • Secure Software Development Cycle Procedure Template

Expected Deliverables:

  • Project Management Methodology Document in the organization
  • Change management methodology or procedures in the organization's information and technology assets document
 

Quick & Simple

Discover Our Cybersecurity Compliance Solutions:

Whether you need to meet and maintain your compliance requirements, help your clients meet them, or verify supplier compliance we have the expertise and solution for you

 CMMC Level 1 Compliance App

CMMC Level 1 Compliance

Become compliant, provide compliance services, or verify partner compliance with CMMC Level 1 Basic Safeguarding of Covered Contractor Information Systems requirements.
 NIST SP 800-171 & CMMC Level 2 Compliance App

NIST SP 800-171 & CMMC Level 2 Compliance

Become compliant, provide compliance services, or verify partner compliance with NIST SP 800-171 and CMMC Level 2 requirements.
 HIPAA Compliance App

HIPAA Compliance

Become compliant, provide compliance services, or verify partner compliance with HIPAA security rule requirements.
 ISO 27001 Compliance App

ISO 27001 Compliance

Become compliant, provide compliance services, or verify partner compliance with ISO 27001 requirements.
 FAR 52.204-21 Compliance App

FAR 52.204-21 Compliance

Become compliant, provide compliance services, or verify partner compliance with FAR 52.204-21 Basic Safeguarding of Covered Contractor Information Systems requirements.
 
Hello! How can we help today? 😃

Chat with Lakeridge

We typically reply within minutes