A.8.9 Configuration management
Establish, document, implement, monitor and review secure configurations for hardware, software, services and networks.
20
artefacts
5
held by a system
3
at each review
moderate
to go live
SIEM / log platform
where the evidence lives
teal = a system already holds it · olive = produced at each review
system holds itEvidence a system already holds
- Hardware baseline config doc · Cloud console / configuration management
- Network device baseline config · Endpoint management (MDM / EDR)
- Change implementation log · SIEM / log platform
- Vulnerability scan results · Vulnerability scanner / patch tooling
- Non compliance findings log · SIEM / log platform
periodic reviewEvidence produced at each review
- Periodic config audit report · Cloud console / configuration management
- Risk assessment document · Policy repository / GRC workspace
- Approval board minutes · Policy repository / GRC workspace
governing documentDocuments that govern the control
- Operating system hardening guide · Policy repository / GRC workspace
- Application security configuration template · Policy repository / GRC workspace
- Change request form · Policy repository / GRC workspace
- Approval email thread · Document repository
- Post change verification report · Document repository
- Remediation action plan · Policy repository / GRC workspace
- Vendor security bulletins · Vendor register / contract repository
- Hardening checklist · Policy repository / GRC workspace
- Baseline security policy · Policy repository / GRC workspace
- Secure configuration standards · Policy repository / GRC workspace
- Exception request form · Policy repository / GRC workspace
- Temporary deviation tracking sheet · Document repository
First move
Start with the 5 of 20 artefacts that already live in a system (SIEM / log platform); keep the periodic reviews but log each one as a dated record with a named reviewer.
Common gaps auditors find
- outdated baselines
- missing change approvals
- infrequent configuration audits
- unauthorized deviations not documented
Do this for your whole sheet
Paste the rows you run your controls from and get this mapping for every control at once, with the periodic-review ones flagged and a first move per row. No account for the first run.
Build my evidence sheetA.8.8 Management of technical vulnerabilities · A.8.10 Information deletion