1.2.8 Configuration files secured and synchronised
Configuration files for NSCs are secured from unauthorized access and kept consistent with active configurations.
5
artefacts
3
held by a system
1
at each review
easy
to go live
Source control / CI pipeline
where the evidence lives
teal = a system already holds it · olive = produced at each review
system holds itEvidence a system already holds
- ACLs on configuration repositories · Source control / CI pipeline
- Backup vs running config comparison reports · Backup / DR tooling
- Access logs to config store · SIEM / log platform
periodic reviewEvidence produced at each review
- Encryption at rest evidence · Cloud console / configuration management
governing documentDocuments that govern the control
- Version control history · Policy repository / GRC workspace
First move
Automate the pull from your Source control / CI pipeline. Pull-request approvals, pipeline test results and deployment records from source control, per release.
Common gaps auditors find
- Running and startup configs diverge
- Backup repository over-permissioned
- No drift detection
Do this for your whole sheet
Paste the rows you run your controls from and get this mapping for every control at once, with the periodic-review ones flagged and a first move per row. No account for the first run.
Build my evidence sheet1.2.7 NSC rule sets reviewed every six months · 1.3.1 Inbound traffic to CDE restricted