2.2.1 Configuration standards are developed, implemented, and maintained to: • Cover all system components. • Address all known security vulnerabilities. • Be consistent with industry-accepted system hardening standards or vendor hardening recommendations. • Be updated
Configuration standards are developed, implemented, and maintained to: • Cover all system components. • Address all known security vulnerabilities. • Be consistent with industry-accepted system hardening standards or ven.
system holds itEvidence a system already holds
- Configuration compliance scan reports · Vulnerability scanner / patch tooling
periodic reviewEvidence produced at each review
none for this control
governing documentDocuments that govern the control
- Hardening standards per OS, database, network device · Policy repository / GRC workspace
- Mapping to CIS or NIST benchmarks · Policy repository / GRC workspace
- Standard update history · Policy repository / GRC workspace
- Coverage matrix versus asset inventory · Policy repository / GRC workspace
First move
Common gaps auditors find
- No standard for one platform
- Standards not aligned to industry benchmark
- No drift scanning
Do this for your whole sheet
Paste the rows you run your controls from and get this mapping for every control at once, with the periodic-review ones flagged and a first move per row. No account for the first run.
Build my evidence sheet2.1.2 Roles and responsibilities for performing activities in Requirement 2 are documented, assigned, and understood · 2.2.2 Vendor default accounts are managed as follows: • If the vendor default account(s) will be used, the default password is changed per Requirement 8.3.6. • If the vendor default account(s) will not be used,