Free compliance framework explorer — browse controls, evidence, and implementation guidance.Subscribe for updates →
SOC 247
ITSP.10.17198
ISO 42001soon
ISO 27001soon

Browse

98 controls

03.04.04Impact analysesITSP.10.171Configuration management

Official Requirement

A. Analyze the security and privacy impacts of changes to the system prior to implementation. B. Verify that the security requirements for the system continue to be satisfied after the system changes have been implemented.

Source: Canadian Centre for Cyber Security ITSP.10.171 (2025), adapted from NIST SP 800-171 Rev. 3

In Plain English

Before making any system change, you must assess its security and privacy impact. After the change is implemented, you must verify that security controls still work as expected. This prevents changes from inadvertently weakening your security posture.

Help us build what matters.

Vote for the next framework, subscribe for updates, and let us know if you'd contribute.

The Trust Services Criteria referenced in this tool are published by the American Institute of Certified Public Accountants (AICPA) and incorporate principles from the Committee of Sponsoring Organizations of the Treadway Commission (COSO). Criteria descriptions are reproduced for reference purposes. All implementation guidance, evidence recommendations, and control language are original work by Truvo Cyber. ISO 27001 and ISO 42001 are standards published by the International Organization for Standardization (ISO). Framework and standard names are the property of their respective owners. This tool is not affiliated with, endorsed by, or certified by AICPA, COSO, or ISO.

© 2026 Truvo Cyber. All rights reserved.

On-premises implementation and evidence

Security and privacy impact analysis for changes

Implementation steps

  1. Require a security impact assessment for every change request, documenting which controls may be affected
  2. Have the security team review and sign off on the impact assessment before the change is approved
  3. After implementation, test affected security controls (firewall rules, access controls, logging) to confirm they still function correctly
  4. Document post-implementation testing results in the change record

Tools / systems

Evidence artifacts

Evidence frequency: Per-change impact analysis and post-change verification