Skip to main content

Proof of competence

ISO/IEC 27001:2022 Annex A · Control 8.9

Configuration Management: A Practical Implementation Guide

Define, deploy and monitor secure configurations throughout the technology lifecycle.

This control concerns establishing, documenting, implementing, monitoring and reviewing configurations of hardware, software, services and networks.

Practical interpretation: A baseline document is not enough. Configuration must be deployable, version-controlled, continuously compared and updated after risk or technology change.

What should the control achieve?

  • Secure baselines exist for relevant technology.
  • Changes are controlled and traceable.
  • Drift is detected and corrected.
  • Exceptions are risk approved and time limited.

Step-by-step implementation

1

Inventory configuration domains

Cover endpoints, servers, cloud, network, applications, databases and security tools.

2

Define baselines

Use vendor guidance, benchmarks, threats and business requirements.

3

Automate deployment

Apply templates, infrastructure as code and configuration management.

4

Control changes

Use review, testing, approval and rollback.

5

Monitor drift

Compare actual state with approved baseline and alert owners.

6

Review and improve

Update after vulnerabilities, incidents and platform changes.

What this could look like in practice

Cloud accounts are created through approved infrastructure code. Continuous posture monitoring identifies public storage or disabled logging and automatically creates remediation tickets.

ActivityPractical implementationEvidence
BaselineSecurity settings are version controlled.Baseline repository
DeploymentAutomated pipeline applies reviewed configuration.Pipeline log
DriftMonitoring detects unauthorized change.Finding
ExceptionBusiness owner approves scoped expiry.Exception record

Implementation evidence

  • Configuration standard
  • Baseline repository
  • Deployment logs
  • Change records
  • Drift reports
  • Exception register
  • Review history
  • Remediation tickets

Useful metrics

  • Assets compliant with baseline
  • Critical drift unresolved
  • Manual configuration changes
  • Expired exceptions

Common mistakes

  • Maintaining baselines no system uses.
  • Allowing direct production changes.
  • Ignoring SaaS and security-tool settings.
  • Auto-remediating without safety controls.
  • Never updating old benchmarks.

Questions an auditor may ask

  • Which baselines apply?
  • How are they deployed?
  • Show drift detection and correction.
  • How are exceptions governed?
Implementation test: Change a representative setting in a test environment and verify detection, ownership, correction and evidence.

Continue through Annex A

Explore the growing library of practical guides for all 93 Annex A controls.

Open the ISO 27001 Annex A Control Library

This independent educational guide paraphrases the practical intent of the control and does not replace the official ISO standards, professional advice or an organization-specific risk assessment. It is not affiliated with or endorsed by ISO.