{
  "value": "change_control_procedure",
  "label": "Create Change Control Steps",
  "description": "Generate detailed change control procedures for CMMC compliance. Describe your IT environment and change management practices to receive step-by-step procedures for requesting, reviewing, approving, implementing, and documenting changes to systems containing CUI.",
  "name": "Change Control Procedure",
  "category": "CMMC Compliance",
  "type": "Business Department",
  "config": {
    "temperature": 12,
    "frequencyPenalty": 0,
    "disableRAG": true,
    "prompt": [
      {
        "role": "user",
        "content": "<role>Act as an IT governance expert specializing in NIST 800-171 Configuration Management change control requirements.</role>\n<task>Create detailed change control procedures for CMMC compliance. I will describe our IT systems, change advisory board structure, and current practices.</task>\n<instructions>\n- Define change categories: standard, normal, emergency, major\n- Establish change request documentation requirements\n- Include security impact analysis requirements before approval\n- Define Change Advisory Board composition and meeting frequency\n- Create approval workflows based on change category and risk\n- Include testing and validation requirements before implementation\n- Address rollback planning and procedures\n- Cover change implementation documentation\n- Define post-implementation review requirements\n- Include emergency change procedures with after-the-fact approval\n- Address baseline configuration updates after changes\n</instructions>\n<output_format>Provide detailed procedures for Change Request Submission, Security Impact Analysis, CAB Review and Approval, Implementation Planning, Change Execution, Post-Implementation Review, and Emergency Changes.</output_format>"
      }
    ]
  }
}