NIST SP 1800-32
NIST SP 1800-32: Supply Chain & Configuration

NIST SP 1800-32 NIST1800-32-23: Change management procedures

Change management procedures. Control from NIST SP 1800-32 framework, domain: NIST SP 1800-32: Supply Chain & Configuration.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 122 controls across 67 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

NIST SP 800-53 Rev 5 · 4 controls

API 1164 · 3 controls

  • API1164-21 TSA Pipeline Security Directive Alignment
  • API1164-22 Configuration management for OT systems
  • API1164-23 Change management procedures
  • AEO-2 Demonstrated Compliance with Customs Requirements
  • AEO-4 Financial Viability
  • P2-S1 Partnership

IEC 62443 · 3 controls

  • IEC62443-21 Supply chain risk management for critical components
  • IEC62443-22 Configuration management for OT systems
  • IEC62443-23 Change management procedures
  • ISO-20400-7.3 Supplier selection
  • ISO-20400-7.4 Contract management and review
  • ISO-20400-7.5 Reviewing and learning

ISO/IEC 27019:2024 · 3 controls

  • ISO27019-22 Configuration management for OT systems
  • ISO27019-23 Change management procedures
  • ISO27019-24 Vulnerability assessment for critical systems
  • NIST-CSF-GV.SC-01 A cybersecurity supply chain risk management program, strategy, objectives, policies, and processes are established and agreed to by organizational stakeholders
  • NIST-CSF-ID.AM-04 Inventories of services provided by suppliers are maintained
  • NIST-CSF-ID.RA-10 Critical suppliers are assessed prior to acquisition
  • NISTSP82-2 OT Risk Assessment and Threat/Vulnerability Identification
  • NISTSP82-5 OT Configuration Management, Patching, Vulnerability Management, and Malware Protection
  • NISTSP82-6 OT Audit, Monitoring, Anomaly Detection, and OT-Specific SOC
  • RMI-DD-3 Red Flag Review
  • RMI-MS-2 Cobalt Standard
  • RMI-RMAP-2 Risk-Based Audit Approach

SASB Standards · 3 controls

  • SASB-1 Business Model + Innovation (BMI)
  • SASB-BMI-3 Supply Chain Management
  • SASB-BMI-5 Physical Impacts of Climate Change

Solvency II · 3 controls

  • SII-P2-09 Outsourcing Requirements
  • SII-P2-12 Written Policies
  • SII-P3-06 SFCR Section B: System of Governance
  • CPS230-27 Identification and Escalation of Incidents and Near Misses
  • CPS230-49 Internal Audit Review of Proposed Critical Operation Outsourcing
  • Clause 10 Change and configuration management
  • Clause 3 Suppliers and service providers
  • CPG-6.A Vendor and Supplier Incident Reporting
  • CPG-6.B Supply Chain Incident Reporting
  • IEC62304-8.2 Change Control
  • IEC62304-9.4 Use Change Control Process
  • A.1 Point-of-Care Testing Additional Requirements
  • ISO-15189-6.8 Externally provided products and services
  • ISO28001-PC-03 Supply Chain Incident Reporting
  • ISO28001-PC-04 Supply Chain Continuity Planning

ISO/IEC 27003:2017 · 2 controls

  • ISO27003-4.2 Understanding the needs and expectations of interested parties
  • ISO27003-8.1 Operational planning and control
  • SSAE18-CC3.4 CC3.4 - COSO Principle 9: Change Management
  • SSAE18-CC8.1 CC8.1 - Infrastructure and Software Change Management
  • CFR211-J-184 Section 211.184 - Component, Drug Product Container, Closure, and Labeling Records
  • AS9100D-8.4 Control of Externally Provided Processes, Products, Services
  • ACQ.4 Supplier Monitoring
  • Mat 03 Responsible Sourcing of Materials

BSI IT-Grundschutz · 1 control

  • BSI-24 Configuration change control
  • CJIS-19 Supply Chain Risk Management
  • FTC-Safeguards-9-Elements 9 Safeguard Elements - Access, Inventory, Encryption, Secure-Dev, MFA, Disposal, Change-Mgmt, Monitoring, Pen-Test (16 CFR 314.4(c))
  • Sapin2-Pillar4-ThirdParty-DueDiligence Pillar 4 - Third-Party Due Diligence (Clients, Suppliers, Intermediaries, M&A)
  • ICAO-ANX17-Chap4-Cargo-Mail-Catering-Stores-Supplies-RegulatedAgent-KnownConsignor ICAO Annex 17 Chapter 4 - Cargo + Mail + Catering + Stores + Supplies Security + Regulated Agent + Known Consignor + Supply Chain

ISO 22316 · 1 control

  • ISO22316-14 Supply chain continuity

ISO 26000:2010 · 1 control

  • ISO-26000-6.6 Fair operating practices
  • ISO-26262-8-8 Change management

ISO 27002:2022 · 1 control

  • 8.32 Change management

ISO 27018:2019 · 1 control

  • 12.1.2 Change management

ISO 30401 · 1 control

  • ISO30401-18 Innovation and change management
  • ISO-41001-8.4 Control of outsourced processes and services
  • ISO-50001-8.3 Procurement
  • ISO20000-06 Change management processes

ISO/IEC 23894:2023 · 1 control

  • ISO23894-A.6 AI System Security

ISO/IEC 27010:2015 · 1 control

  • 27010-15.1 Incident Management

ISO/IEC 27011:2024 · 1 control

  • 27011-5.6 Supplier relationships and telecom supply chain

ISO/TS 22317:2021 · 1 control

  • ISO22317-14 Supply chain continuity

ISO/TS 22318:2021 · 1 control

  • ISO22318-14 Supply chain continuity

ITIL 4 · 1 control

  • ITIL4-06 Change management processes
  • NISTPF-8 Protect-P Information Protection Processes (PR.PO-P)

NIST SP 800-190 · 1 control

  • NRFCS-1 Retail Cybersecurity Governance, Policy, and Regulatory Change Management
  • PASONE-3 Personnel Security, Vetting, Awareness, and Training
  • PICSGMP-7 Chapter 7: Outsourced Activities and Supplier Management
  • PSPF-DIR-001-2024 Direction 001-2024: Foreign Ownership, Control or Influence - Technology Assets
  • SAEIGHT-7 Management System, Worker Engagement, Continuous Improvement

SOC 2 · 1 control

  • SOC2-CC8.1 CC8.1 Managing changes to procedures, software, data and infrastructure
  • 2.7.2 Food Fraud Plan
  • SOCI-CIRMP-SUPPLY CIRMP hazard vector: Supply chain
  • IM8-TPM.4 Supply Chain Risk Management

South Korea ISMS-P · 1 control

  • ISMSP-PI-03 Third-Party Provision and Outsourcing
  • UKOPRES-5 Third-Party Risk, Concentration Risk
  • UKGAMBLE-4 Resilience and Incident Response
  • UK-TSA-NET-03 Supply Chain Security

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in NIST SP 1800-32: Supply Chain & Configuration

Query this from an agent

The graph holds this control, the 122 it maps to, and the evidence behind each claim, over MCP and REST.