8.9 Configuration management
Requires configurations of hardware, software, services and networks, including their security configurations, to be established, documented, implemented, monitored and reviewed. Supporting material frames this as a stan
5
artefacts
2
held by a system
3
at each review
moderate
to go live
Cloud console / configuration management
where the evidence lives
teal = a system already holds it · olive = produced at each review
system holds itEvidence a system already holds
- Documented secure configuration baselines per platform and service, and their basis such as a recognised benchmark · Cloud console / configuration management
- Automated compliance monitoring output showing conformance and drift, with the frequency of measurement · SIEM / log platform
periodic reviewEvidence produced at each review
- Evidence baselines are implemented, sampled across live systems rather than assumed from the build image · Cloud console / configuration management
- Records of exceptions to baseline, with justification, approval and expiry · Cloud console / configuration management
- Change control over the baselines themselves, showing review as platforms and threats change · Cloud console / configuration management
governing documentDocuments that govern the control
none for this control
First move
Start with the 2 of 5 artefacts that already live in a system (Cloud console / configuration management); keep the periodic reviews but log each one as a dated record with a named reviewer.
Common gaps auditors find
- Baseline applied at build with no ongoing measurement, so configuration drifts unchecked from day one
- Exceptions accumulating with no expiry, until the exception list describes the actual estate
- Cloud and container configuration excluded because the baseline concept was defined for servers
- Monitoring detects drift and generates no action, so the finding recurs every cycle
Do this for your whole sheet
Paste the rows you run your controls from and get this mapping for every control at once, with the periodic-review ones flagged and a first move per row. No account for the first run.
Build my evidence sheet8.8 Management of technical vulnerabilities · 8.10 Information deletion