Requirement 2: Apply secure configurations to all system components
Default passwords and settings are public knowledge. Every component must be hardened before it goes live.
Sub-requirements
2.1
Processes and mechanisms are defined and understood
2 defined requirementsDocument configuration standards and ownership.
View defined requirements →2.2
System components are configured and managed securely
7 defined requirementsApply hardening baselines, change all vendor defaults, and remove unnecessary services/accounts.
View defined requirements →2.3
Wireless environments are configured and managed securely
2 defined requirementsChange wireless defaults (keys, SNMP, passwords) and use strong encryption.
View defined requirements →Tips
- ›Base hardening on a recognised benchmark (e.g. CIS) and enforce it with configuration management.
- ›Keep an inventory of components mapped to their configuration standard.
Evidence to keep
- ✓Hardening/configuration standards
- ✓System inventory
- ✓Sample configurations showing defaults changed
Example
A team builds servers from a CIS-hardened image via Terraform, with no default credentials and only required ports open, recorded in an inventory.
Policy templates for this control
Use these starting documents to turn the control into evidence. Adapt each template to your scope, systems, legal obligations and actual operating process.
Asset management policyUse for ISO 27001 A.5.9, A.5.10, A.5.11, A.7.9 to A.7.14, SOC 2 Security, and PCI DSS asset inventory expectations.Change management policyUse for ISO 27001 A.8.32, A.8.9, SOC 2 change management criteria, and PCI DSS requirement 6 change controls.Cryptography and key management policyUse for ISO 27001 A.8.24, secure authentication, encryption, SOC 2 Security, and PCI DSS encryption requirements.Password and authentication policyUse for ISO 27001 A.5.17, A.8.5, SOC 2 Security, and PCI DSS requirement 8 authentication controls.
Open the control-to-policy map