ISO 20000-1
ISO 20000-1: Service Transition

ISO 20000-1 10: Configuration management

Configuration management. Control from ISO 20000-1 framework, domain: ISO 20000-1: Service Transition.

Maintained by Gerard BlokdykControl text last updated

What else in your programme already covers this

This control maps to 83 controls across 45 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

  • ASD37-04 User application hardening (Essential)
  • ASD37-10 Server application hardening (Very Good)
  • ASD37-11 Operating system hardening (Very Good)

BSI IT-Grundschutz · 3 controls

  • BSI-23 Baseline configuration establishment
  • BSI-24 Configuration change control
  • BSI-26 System component inventory

NIST SP 800-53 Rev 5 · 3 controls

API 1164 · 2 controls

IEC 62443 · 2 controls

ISO 27017 · 2 controls

ISO 27018 · 2 controls

ISO 27019 · 2 controls

NIST SP 1800-32 · 2 controls

NIST SP 800-145 · 2 controls

  • NISTSP145-7 Cloud Procurement Standards Aligned to NIST SP 800-145 Definition
  • NISTSP145-8 Governance, Reporting, and Stakeholder Education on Cloud Definition

NIST SP 800-190 · 2 controls

  • NISTSP82-1 OT Security Program Governance, Policy, Roles, and Safety-Security Integration
  • NISTSP82-5 OT Configuration Management, Patching, Vulnerability Management, and Malware Protection
  • Clause 10 Change and configuration management
  • CJIS-7 Configuration Management

ISO 10007:2017 · 1 control

  • 5.2 Configuration management planning

ISO 27002:2022 · 1 control

  • 8.9 Configuration management

ISO/IEC 27400:2022 · 1 control

ITIL 4 · 1 control

MTCS (Singapore) · 1 control

NERC CIP · 1 control

  • NERCCIP-5 System Security Management + Configuration Change Management and Vulnerability Assessments (CIP-007 + CIP-010)
  • NISTPF-8 Protect-P Information Protection Processes (PR.PO-P)

NIST SP 800-144 · 1 control

  • NISTSP144-7 Cloud Workload Protection, Containers, Serverless, and Configuration

NIST SP 800-146 · 1 control

  • NISTSP146-4 IaaS Operational Recommendations and Workload Hardening

OSFI B-13 · 1 control

  • OSFIB13-3 Cyber Security: Identification, Protection, Detection, Response, Recovery
  • OMANCS-5 Network, Endpoint, System Development, and Configuration Security
  • OPENBANK-3 Mutual TLS, Token Binding, Request Signing (JWS), Key Management

PCI P2PE · 1 control

PCI PIN Security · 1 control

PCI SSF · 1 control

PSD2 SCA · 1 control

  • PSDTWO-2 SCA Exemptions and Risk-Based Authentication
  • CISABD-1 Take Ownership of Customer Security Outcomes

South Korea ISMS-P · 1 control

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in ISO 20000-1: Service Transition

Query this from an agent

The graph holds this control, the 83 it maps to, and the evidence behind each claim, over MCP and REST.