ISO/IEC 27001:2022 Annex A · Control 8.9
Configuration Management: A Practical Implementation Guide
Define, deploy and monitor secure configurations throughout the technology lifecycle.
This control concerns establishing, documenting, implementing, monitoring and reviewing configurations of hardware, software, services and networks.
What should the control achieve?
- Secure baselines exist for relevant technology.
- Changes are controlled and traceable.
- Drift is detected and corrected.
- Exceptions are risk approved and time limited.
Step-by-step implementation
Inventory configuration domains
Cover endpoints, servers, cloud, network, applications, databases and security tools.
Define baselines
Use vendor guidance, benchmarks, threats and business requirements.
Automate deployment
Apply templates, infrastructure as code and configuration management.
Control changes
Use review, testing, approval and rollback.
Monitor drift
Compare actual state with approved baseline and alert owners.
Review and improve
Update after vulnerabilities, incidents and platform changes.
What this could look like in practice
Cloud accounts are created through approved infrastructure code. Continuous posture monitoring identifies public storage or disabled logging and automatically creates remediation tickets.
| Activity | Practical implementation | Evidence |
|---|---|---|
| Baseline | Security settings are version controlled. | Baseline repository |
| Deployment | Automated pipeline applies reviewed configuration. | Pipeline log |
| Drift | Monitoring detects unauthorized change. | Finding |
| Exception | Business owner approves scoped expiry. | Exception record |
Implementation evidence
- Configuration standard
- Baseline repository
- Deployment logs
- Change records
- Drift reports
- Exception register
- Review history
- Remediation tickets
Useful metrics
- Assets compliant with baseline
- Critical drift unresolved
- Manual configuration changes
- Expired exceptions
Common mistakes
- Maintaining baselines no system uses.
- Allowing direct production changes.
- Ignoring SaaS and security-tool settings.
- Auto-remediating without safety controls.
- Never updating old benchmarks.
Questions an auditor may ask
- Which baselines apply?
- How are they deployed?
- Show drift detection and correction.
- How are exceptions governed?
Continue through Annex A
Explore the growing library of practical guides for all 93 Annex A controls.
Open the ISO 27001 Annex A Control LibraryThis independent educational guide paraphrases the practical intent of the control and does not replace the official ISO standards, professional advice or an organization-specific risk assessment. It is not affiliated with or endorsed by ISO.