2.2.4 Only necessary services enabled
Only necessary services, protocols, daemons, and functions are enabled. All unnecessary functionality is removed or disabled.
5
artefacts
3
held by a system
1
at each review
easy
to go live
Cloud console / configuration management
where the evidence lives
teal = a system already holds it · olive = produced at each review
system holds itEvidence a system already holds
- Configuration audit output · Cloud console / configuration management
- Removal scripts and logs · SIEM / log platform
- Vulnerability scan reports · Vulnerability scanner / patch tooling
periodic reviewEvidence produced at each review
- Build review checklist · Document repository
governing documentDocuments that govern the control
- Per-platform allowed service list · Document repository
First move
Automate the pull from your Cloud console / configuration management. Configuration snapshots and change history from the cloud console or IaC repository, diffed against the baseline.
Common gaps auditors find
- Sample systems with unused daemons running
- No baseline scan
- Bloated default images
Do this for your whole sheet
Paste the rows you run your controls from and get this mapping for every control at once, with the periodic-review ones flagged and a first move per row. No account for the first run.
Build my evidence sheet2.2.3 Primary functions isolated or secured to highest level · 2.2.5 Insecure services or protocols documented