EvidenceSheet

8.9 Configuration management

Requires configurations of hardware, software, services and networks, including their security configurations, to be established, documented, implemented, monitored and reviewed. Supporting material frames this as a stan

5
artefacts
2
held by a system
3
at each review
moderate
to go live
Cloud console / configuration management
where the evidence lives
teal = a system already holds it · olive = produced at each review

system holds itEvidence a system already holds

  • Documented secure configuration baselines per platform and service, and their basis such as a recognised benchmark · Cloud console / configuration management
  • Automated compliance monitoring output showing conformance and drift, with the frequency of measurement · SIEM / log platform

periodic reviewEvidence produced at each review

  • Evidence baselines are implemented, sampled across live systems rather than assumed from the build image · Cloud console / configuration management
  • Records of exceptions to baseline, with justification, approval and expiry · Cloud console / configuration management
  • Change control over the baselines themselves, showing review as platforms and threats change · Cloud console / configuration management

governing documentDocuments that govern the control

none for this control

First move

Start with the 2 of 5 artefacts that already live in a system (Cloud console / configuration management); keep the periodic reviews but log each one as a dated record with a named reviewer.

Common gaps auditors find

Do this for your whole sheet

Paste the rows you run your controls from and get this mapping for every control at once, with the periodic-review ones flagged and a first move per row. No account for the first run.

Build my evidence sheet

8.8 Management of technical vulnerabilities · 8.10 Information deletion