- 2.150.1 Configuration Management Policy
- 2.150.1.1 Program Scope and Objectives
- 2.150.1.1.1 Background
- 2.150.1.1.2 Authority
- 2.150.1.1.3 Responsibilities
- 2.150.1.1.4 Program and Management Review
- 2.150.1.1.5 Program Controls
- 2.150.1.1.6 Terms/Definitions/Acronyms
- 2.150.1.1.6.1 Terms and Definitions
- 2.150.1.1.6.2 Acronyms
- 2.150.1.1.7 Related Resources
- 2.150.1.2 Purpose
- 2.150.1.3 Scope
- 2.150.1.4 Mandates
Part 2. Information Technology
Chapter 150. Configuration and Change Management
Section 1. Configuration Management Policy
2.150.1 Configuration Management Policy
Manual Transmittal
July 16, 2026
Purpose
(1) This transmits revised IRM 2.150.1, Configuration Management, Configuration Management Policy.
Material Changes
(1) IRM 2.150.1.1 Program Scope and Objectives. Revised this section to shift from a process-focused description to enterprise-wide Configuration Management (CM) governance to strengthen security, integrity, traceability, and operational reliability.
(2) IRM 2.150.1.1.2 Authority. Expanded authority references to include NIST, FIPS, IEEE, and ITIL standards to align with federal requirements and industry best practices.
(3) IRM 2.150.1.1.3 Responsibilities. Updated roles and responsibilities to establish enterprise accountability across CIO, system owners, engineering, and cybersecurity to improve governance clarity and ownership.
(4) IRM 2.150.1.1.4 Program and Management Review. Revised this section to emphasize evaluation of control effectiveness, baseline integrity, and remediation performance to enhance oversight and audit readiness.
(5) IRM 2.150.1.1.5 Program Controls. Updated program controls to define an operational control framework, including baseline management, change authorization, monitoring, and audit readiness, to improve consistency, enforceability, and audit readiness.
(6) IRM 2.150.1.1.6 Terms/Definitions/Acronyms. Modernized terminology to include technical, security, and monitoring concepts such as CMDB, continuous monitoring, and Security Impact Analysis to reflect current CM practices and improve clarity.
(7) IRM 2.150.1.2 Purpose. Expanded the purpose to include enterprise security, compliance, modernization, audit readiness, and protection of taxpayer data to align with broader IRS Information Technology (IT) objectives.
(8) IRM 2.150.1.3 Scope. Broadened scope to explicitly include cloud, hybrid, and externally hosted environments across all lifecycle phases to ensure enterprise-wide applicability.
(9) IRM 2.150.1.4 Mandates. Revised mandates to establish enterprise-level Configuration Management governance through control-based policy requirements, replacing prior lifecycle and process-oriented structure. Updates emphasize configuration integrity, traceability to authorized changes, integration with Change Management (IRM 2.125.1), use of authoritative systems of record including the CMDB, and continuous monitoring, while aligning detailed procedural and implementation requirements to IRM 2.150.2 to strengthen governance clarity, control integration, and audit readiness.
(10) Editorial Changes Made editorial updates throughout the IRM for clarity, consistency, formatting, and alignment with current terminology and standards.
Effect on Other Documents
This IRM supersedes IRM 2.150.1 revision date April 1, 2024.Audience
This IRM section applies to all Internal Revenue Service (IRS) IT organizations and personnel responsible for the planning, design, development, implementation, operation, security, maintenance, and oversight of IRS information systems and technology assets.Effective Date
(07-16-2026)
Kaschit Pandya
Chief Information Officer
Purpose. This IRM establishes enterprise Configuration Management (CM) policy for IRS IT systems and services. Configuration Management governs the identification, control, and maintenance of configuration items (CIs) and their relationships to ensure configuration integrity, traceability, and alignment with approved system states. This policy ensures that configuration baselines reflect only authorized changes in accordance with Change Management policy, supports system security and authorization within defined boundaries, and maintains accurate and authoritative configuration information across on-premises, cloud, and hybrid environments in alignment with ITIL 4, IEEE Software Configuration Management, and ISO standards.
Audience. This policy applies to all IRS IT organizations, contractors, and stakeholders responsible for the management, control, implementation, or oversight of configuration items and configuration management practices across enterprise IT systems, services, and environments.
Policy Owner. Strategy & Product Management (S&PM) - IT.
Program Owner. Infrastructure Tech Ops (ITO) Product Management within S&PM - IT.
Primary Stakeholders. IT organizations responsible for implementing configuration management controls, maintaining configuration data, or managing system and service configurations are primary stakeholders in this policy.
Contact Information. To recommend changes or to make any suggestions to this IRM section, e-mail the Configuration Management Program Management Office (CM PMO): it.cm.process@irs.gov
IRS IT operates within a complex and evolving enterprise environment that requires effective governance of system configurations to manage operational risk, maintain cybersecurity, and support federal compliance requirements.
Configuration Management provides the foundation for ensuring that IT systems and services remain in a controlled, secure, and auditable state. It establishes authoritative configuration information, supports system integrity and authorization, and enables traceability across enterprise environments, including on-premises and cloud.
This policy aligns with recognized industry standards and practices, including ITIL 4, IEEE Software Configuration Management, and ISO standards, and operates in coordination with Change Management to ensure that configuration states reflect only authorized and approved changes.
Configuration Management policy is established pursuant to federal law, Office of Management and Budget (OMB) policy, and IRS policy governing information technology and cybersecurity. This policy is supported by federal control frameworks and recognized industry standards for configuration management:
Federal Information Security Modernization Act of 2014 (FISMA), Pub. L. 113–283, codified at 44 U.S.C. § 3551 et seq.
OMB Circular A-130, Managing Information as a Strategic Resource
IRM 1.2.1.3 Policy Statements for Information Technology Activities
IRM 10.8.1 Information Technology (IT) Security, Policy and Guidance
FIPS 199, Standards for Security Categorization of Federal Information and Information Systems
FIPS 200, Minimum Security Requirements for Federal Information and Information Systems
NIST Special Publication 800-53, Security and Privacy Controls for Information Systems and Organizations
NIST Special Publication 800-37, Risk Management Framework for Information Systems and Organizations
NIST Special Publication 800-128, Guide for Security-Focused Configuration Management of Information Systems
IEEE 828, Configuration Management in Systems and Software Engineering
Configuration Management is required to ensure that IRS IT systems and services maintain authorized, controlled, and auditable configuration states in compliance with federal cybersecurity requirements and IRS policy.
Chief Information Officer (CIO), IRS IT
The CIO provides executive sponsorship and enterprise oversight for Configuration Management and ensures alignment with federal mandates, cybersecurity requirements, and enterprise risk management.
IT Executives and Domain Leadership
IT Executives and Domain Leadership are accountable for implementing Configuration Management within their areas of responsibility and ensuring compliance with this policy, including enforcement of configuration governance and management of associated risks.
Configuration Management Program Management Office (CM PMO)
The CM PMO establishes and maintains enterprise Configuration Management policy, standards, and governance frameworks; provides authoritative guidance; and monitors enterprise-level compliance and risk.
The CM PMO provides governance oversight and does not perform operational configuration management activities.
The CM PMO provides governance oversight and does not execute operational configuration activities, which remain the responsibility of system owners and engineering organizations.
System Owners
System Owners are accountable for ensuring that Configuration Management requirements are implemented within their systems, including establishment of configuration baselines, maintenance of accurate configuration information, and ensuring that configurations reflect authorized system states.
Engineering and Operations Organizations
Engineering and Operations organizations are responsible for implementing Configuration Management controls in accordance with approved policies, standards, and authorized configurations.
Cybersecurity Organization
The Cybersecurity organization establishes security configuration requirements, ensures alignment with security controls and authorization requirements, and provides oversight of configuration compliance related to system security posture.
Configuration Item (CI) Owners
Configuration Item (CI) Owners are responsible for maintaining the integrity and accuracy of configuration information and ensuring that assigned configuration items remain aligned with approved baselines.
All IT Personnel and Contractors
All personnel are responsible for complying with this policy and ensuring that their activities maintain configuration integrity and alignment with approved configurations.
Configuration Management is subject to periodic enterprise oversight to assess compliance with this policy, effectiveness of configuration controls, and overall governance maturity.
Reviews shall address:
Maintenance of approved configuration baselines.
Accuracy and completeness of configuration records.
Effectiveness of change control integration.
Timeliness of remediation for identified deficiencies.
Review results shall be documented, reported to appropriate governance authorities, and tracked through resolution.
Program Controls establish enterprise requirements and governance expectations for Configuration Management, including:
Configuration Item (CI) identification and classification requirements.
Baseline definition, control, and version management requirements.
Configuration change control and traceability requirements.
Configuration status accounting and reporting requirements.
Configuration verification and audit requirements.
These controls support compliance with federal cybersecurity requirements and ensure that configuration states remain authorized, controlled, and auditable.
The tables in the Terms and Definitions and Acronyms sections define terms and acronyms used in this IRM.
-
The following terms and definitions are used in this IRM.
Term Definition Baseline A formally approved configuration of a system or configuration item at a defined point in time that serves as the basis for control and comparison. Configuration Item (CI) An asset, component, service, or system element subject to configuration management control with defined attributes and relationships. Configuration Management (CM) A governance discipline that establishes and maintains the integrity of systems and services through configuration identification, control, status accounting, and verification. Configuration Control The enforcement of configuration requirements to ensure that configuration states remain aligned with approved and authorized system configurations. Configuration Status Accounting The recording and reporting of configuration information, including the status of configuration items and baselines. Configuration Verification The validation that configuration items and baselines are consistent with approved configurations and accurately reflect the operational environment. Configuration Audit An independent assessment to determine whether configuration items and records conform to approved baselines and established requirements. Configuration Integrity The condition in which configuration information is accurate, complete, and consistent with approved system states. Unauthorized Change A change to a configuration item that has not been approved in accordance with established change authorization requirements.
The following related Internal Revenue Manual (IRM) sections provide supporting guidance associated with Configuration Management:
IRM 2.150.2 Configuration Management Process
IRM 2.125.1 Change Management Policy
IRM 2.125.2 Change Management Process
IRM 2.22.1 Unified Work Request (UWR) Process
IRM 10.8.1 Information Technology (IT) Security, Policy and Guidance
These resources provide procedural and operational guidance supporting the implementation of Configuration Management policy.
Configuration Management establishes a foundational governance control to ensure that IRS IT systems operate from authorized, secure, and auditable configuration baselines. It supports federal cybersecurity compliance, modernization initiatives, audit readiness, and protection of taxpayer data, and ensures consistent configuration control throughout the product delivery lifecycle.
This policy applies to all IRS IT systems, applications, infrastructure, platforms, services, and associated configuration items and records, including those in on-premises, cloud, hybrid, and externally managed environments.
This policy applies across all environments, including production, development, test, and contingency, throughout the product delivery lifecycle.
This policy applies to all IRS IT personnel, contractors, service providers, and partner organizations responsible for managing, developing, operating, securing, or maintaining IRS technology assets and configuration information.
Configuration Management shall be implemented across IRS IT to ensure configuration integrity, traceability, and alignment with authorized system states.
Configuration Management shall be governed through enterprise-defined and enforced controls that ensure:
CIs, baselines, and configuration records remain authorized, accurate, and complete.
Configuration states are fully traceable to approved changes in accordance with IRM 2.125.1, Change Management Policy.
Configuration information is maintained as authoritative and auditable across all environments, including on-premises, cloud, and hybrid.
Configuration states are subject to continuous monitoring to identify unauthorized or unintended changes and maintain alignment with approved baselines.
Configuration Management is integrated across the system lifecycle.
Configuration governance supports security, compliance, audit readiness, and risk management objectives.
Configuration changes are subject to formal authorization, risk and Security Impact Assessment (SIA), and segregation of duties in accordance with IRM 2.125.1.4 (Change Management Policy).
Configuration information is maintained within authoritative systems of record, including the Configuration Management Database (CMDB), in accordance with IRM 2.150.2 and integrated with Change Management (IRM 2.125.1).
Configuration Management shall be integrated with enterprise Change Management to ensure that:
Only authorized and approved changes result in modifications to configuration baselines and records.
Configuration information reflects the current and approved system state.
Traceability is maintained between configuration items, baselines, and associated change records.
Configuration Management shall establish enterprise accountability and enforcement to ensure compliance with this policy. Non-compliance shall be subject to corrective action and risk escalation in accordance with IRS governance.
Detailed procedural, operational, and implementation requirements for Configuration Management, including lifecycle activities, controls, and supporting artifacts, are defined in IRM 2.150.2, Configuration Management Process.