Configuration management
Purpose
Establish, document, implement, monitor and review secure configurations across hardware, software, services and networks.
How to meet this control
In short: Establish, document, implement, monitor and review configurations.
- Step 01Define hardening baselines using recognised guidance such as CIS Benchmarks or vendor security baselines for each operating system and service
- Step 02Enforce configuration through infrastructure-as-code (Terraform, Ansible, cloud landing zones) so systems are built to the standard rather than hand-configured
- Step 03Apply cloud guardrails such as Azure Policy, AWS Config or SCPs to prevent and flag non-compliant resources
- Step 04Change all default passwords and disable unused accounts, ports, services and functions at build time
- Step 05Continuously monitor configuration drift with a posture tool (Defender for Cloud, AWS Config, Wiz) and auto-remediate or ticket deviations
- Step 06Route any configuration change through change management and version-control the templates
Tip: Use hardening baselines and infrastructure-as-code to enforce them.
What ISO 27002 says to cover
Reference points from the ISO/IEC 27002:2022 guidance for this control. Use them to check the steps above cover everything relevant to you.
- ›Define processes and tools to enforce configurations for new and existing systems
- ›Create secure configuration templates using vendor and independent security guidance
- ›Review and update templates when new threats, vulnerabilities or versions appear
- ›Minimise privileged identities and disable unused or insecure accounts, functions and services
- ›Restrict access to powerful utilities, change default passwords immediately and synchronise clocks
- ›Apply automatic session time-outs and confirm licence requirements are met
- ›Record configurations, log every change and route changes through change management
- ›Monitor configurations against templates and correct deviations, protecting templates as confidential
Audit evidence to keep
- - Hardening baseline or CIS Benchmark configuration documents per platform
- - Infrastructure-as-code repository enforcing the baseline
- - Cloud policy or guardrail configuration with a sample compliance report
- - Configuration drift or posture report showing deviations and remediation
- - Change records covering configuration template updates
Common mistakes
- - Writing a policy but not operating the process
- - Keeping evidence in personal folders where auditors cannot trace it
- - Letting exceptions stay open with no owner or expiry date
Owner, cadence, and proof
Assign one accountable owner for A.8.9. Review this control at least annually, after related incidents, and whenever the underlying process, supplier, system, office, or legal obligation changes. The control is audit-ready when the owner can show the policy or procedure, the latest operating evidence, the latest review, and any open exceptions with due dates.
Policy templates for this control
Use these starting documents to turn the control into evidence. Adapt each template to your scope, systems, legal obligations and actual operating process.