Typical severity: High. Likelihood of attack: Low. During the system build process, the system is deliberately misconfigured by the alteration of the build data. Access to system configuration data files and build processes is susceptible to deliberate misconfiguration of the system.
Implement configuration management security practices that protect the integrity of software and associated data. | Monitor and control access to the configuration management system. | Harden centralized repositories against attack. | Establish acceptance criteria for configuration management check-in to assure integrity. | Plan for and audit the security of configuration management administration processes.