PW.9.2: Implement the default settings (or groups of default settings, if applicable), and document each setting for software administrators.
Example 1: Verify that the approved configuration is in place for the software.
Example 2: Document each setting’s purpose, options, default value, security relevance, potential operational impact, and relationships with other settings.
Example 3: Use authoritative programmatic technical mechanisms to record how each setting can be implemented and assessed by software administrators.
Example 4: Store the default configuration in a usable format and follow change control practices for modifying it (e.g., configuration-as-code).
CMMI Maturity
Description
Implement the default settings (or groups of default settings, if applicable), and document each setting for software administrators.