ISO 27002:2022
Technological controls – ISO 27002:2022

ISO 27002:2022 8.9: Configuration management

The organization is to set, record, apply, watch and review how its hardware, software, services and networks are configured, security settings included. Purpose: keep hardware, software, services and networks working correctly with the security settings they need, and keep settings from being altered without approval or by mistake. Guidance: define and run processes and tools that enforce defined configurations for hardware, software, services such as cloud services, and networks, both on new installations and through the life of operational systems, with roles, responsibilities and procedures that keep every configuration change under control. Standard secure configuration templates should draw on public guidance such as vendor and independent security organization baselines, reflect the protection level needed, support the organization's policies and standards, and be feasible in its context; review them periodically and update them for new threats, vulnerabilities or new software and hardware versions. Templates should consider: keeping the number of privileged or administrator identities low; disabling unnecessary, unused or insecure identities; disabling or restricting unneeded functions and services; restricting access to powerful utilities and host parameters; clock synchronization; changing vendor default credentials immediately after installation and reviewing other security-relevant defaults; inactivity timeouts that log devices off; and checking licence compliance (5.32). Managing: record established configurations and log every change, stored securely, for example in a configuration database or templates, with changes going through change management (8.32); records can hold the current owner or contact, date of last change, template version and links to related assets' configurations. Monitoring: use a broad range of system management tooling (maintenance utilities, remote support, enterprise management, backup and restore) and review regularly to check settings, evaluate password strength and assess activity; compare actual settings with target templates and correct deviations by automatic enforcement or by manual analysis and corrective action. Other information: system documentation often holds configuration detail; hardening is part of configuration management; it can be joined with asset management; automation such as infrastructure as code is usually more effective; templates and targets can be confidential and should be protected.

Maintained by Gerard BlokdykControl text last updated

What else in your programme already covers this

This control maps to 200 controls across 53 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

ACSC Essential Eight · 23 controls

  • E8-MACRO-ML1 Configure Microsoft Office Macro Settings (ML1)
  • E8-UAH-ML2 User Application Hardening - Maturity Level 2
  • E8-ADMIN-ISM-1686 Restrict administrative privileges (ISM-1686): Credential Guard functionality is enabled
  • E8-ADMIN-ISM-1861 Restrict administrative privileges (ISM-1861): Local Security Authority protection functionality is enabled
  • E8-ADMIN-ISM-1896 Restrict administrative privileges (ISM-1896): Memory integrity functionality is enabled
  • E8-ADMIN-ISM-1897 Restrict administrative privileges (ISM-1897): Remote Credential Guard functionality is enabled
  • E8-UAH-ISM-1412 User application hardening (ISM-1412): Web browsers are hardened using ASD and vendor hardening guidance, with the most restrictive guidance taking precedence when conflicts occur
  • E8-UAH-ISM-1485 User application hardening (ISM-1485): Web browsers do not process web advertisements from the internet
  • E8-UAH-ISM-1486 User application hardening (ISM-1486): Web browsers do not process Java from the internet
  • E8-UAH-ISM-1542 User application hardening (ISM-1542): Microsoft Office is configured to prevent activation of Object Linking and Embedding packages
  • E8-UAH-ISM-1585 User application hardening (ISM-1585): Web browser security settings cannot be changed by users
  • E8-UAH-ISM-1621 User application hardening (ISM-1621): Windows PowerShell 2.0 is disabled or removed
  • E8-UAH-ISM-1622 User application hardening (ISM-1622): PowerShell is configured to use Constrained Language Mode
  • E8-UAH-ISM-1654 User application hardening (ISM-1654): Internet Explorer 11 is disabled or removed
  • E8-UAH-ISM-1655 User application hardening (ISM-1655): .NET Framework 3.5 (includes .NET 2.0 and 3.0) is disabled or removed
  • E8-UAH-ISM-1667 User application hardening (ISM-1667): Microsoft Office is blocked from creating child processes
  • E8-UAH-ISM-1668 User application hardening (ISM-1668): Microsoft Office is blocked from creating executable content
  • E8-UAH-ISM-1669 User application hardening (ISM-1669): Microsoft Office is blocked from injecting code into other processes
  • E8-UAH-ISM-1670 User application hardening (ISM-1670): PDF software is blocked from creating child processes
  • E8-UAH-ISM-1823 User application hardening (ISM-1823): Office productivity suite security settings cannot be changed by users
  • E8-UAH-ISM-1824 User application hardening (ISM-1824): PDF software security settings cannot be changed by users
  • E8-UAH-ISM-1859 User application hardening (ISM-1859): Office productivity suites are hardened using ASD and vendor hardening guidance, with the most restrictive guidance taking precedence when conflicts occur
  • E8-UAH-ISM-1860 User application hardening (ISM-1860): PDF software is hardened using ASD and vendor hardening guidance, with the most restrictive guidance taking precedence when conflicts occur

FedRAMP High · 17 controls

  • CM-1 Policy and Procedures
  • CM-12(1) Information Location | Automated Tools to Support Information Location (CM-12(1))
  • CM-2 Baseline Configuration
  • CM-2(2) Automation Support for Accuracy and Currency
  • CM-2(3) Retention of Previous Configurations
  • CM-2(7) Configure Systems and Components for High-Risk Areas
  • CM-6 Configuration Settings
  • CM-6(1) Automated Management, Application, and Verification
  • CM-7(1) Periodic Review
  • CM-7(5) Authorized Software Allow-by-Exception
  • CM-9 Configuration Management Plan
  • SA-10 Developer Configuration Management
  • SC-7(12) Boundary Protection | Host-based Protection (SC-7(12))
  • SI-7 Software, Firmware, and Information Integrity
  • SI-7(1) Integrity Checks
  • SI-7(7) Integration of Detection and Response
  • SI-8(2) Spam Protection | Automatic Updates (SI-8(2))

FedRAMP Moderate · 17 controls

  • CM-1 Policy and Procedures
  • CM-12(1) Information Location | Automated Tools to Support Information Location (CM-12(1))
  • CM-2 Baseline Configuration
  • CM-2(2) Automation Support for Accuracy and Currency
  • CM-2(3) Retention of Previous Configurations
  • CM-2(7) Configure Systems and Components for High-Risk Areas
  • CM-6 Configuration Settings
  • CM-6(1) Automated Management, Application, and Verification
  • CM-7(1) Periodic Review
  • CM-7(5) Authorized Software Allow-by-Exception
  • CM-9 Configuration Management Plan
  • SA-10 Developer Configuration Management
  • SC-7(12) Boundary Protection | Host-based Protection (SC-7(12))
  • SI-7 Software, Firmware, and Information Integrity
  • SI-7(1) Integrity Checks
  • SI-7(7) Integration of Detection and Response
  • SI-8(2) Spam Protection | Automatic Updates (SI-8(2))

NIST SP 800-53 Rev 5 · 15 controls

PCI DSS 4.0 · 15 controls

  • 1.2.1 1.2.1 Ruleset configuration standards for NSCs
  • 1.2.6 1.2.6 Security features for insecure services in use
  • 1.2.8 1.2.8 NSC configuration files secured and consistent
  • 1.5.1 1.5.1 Security controls on dual-connected devices
  • 10.3.4 10.3.4 File integrity monitoring on audit logs
  • 11.5.2 11.5.2 Change detection on critical files
  • 11.6.1 11.6.1 Payment page tamper detection
  • 12.6.1 12.6.1 Formal security awareness program
  • 2.2.1 2.2.1 System configuration standards maintained
  • 2.2.2 2.2.2 Vendor default accounts managed
  • 2.2.4 2.2.4 Only necessary functionality enabled
  • 2.2.5 2.2.5 Insecure services, protocols or daemons secured
  • 2.2.6 2.2.6 System security parameters configured against misuse
  • 2.3.1 2.3.1 Wireless vendor defaults changed or confirmed secure
  • 6.5.1 6.5.1 Change control procedure for production

CIS Controls v8 · 11 controls

  • CIS-10.5 Enable Anti-Exploitation Features
  • CIS-12.1 Ensure Network Infrastructure is Up-to-Date
  • CIS-13.5 Manage Access Control for Remote Assets
  • CIS-16.7 Use Standard Hardening Configuration Templates for Application Infrastructure
  • CIS-2.3 Address Unauthorized Software
  • CIS-4.1 Establish and Maintain a Secure Configuration Process
  • CIS-4.2 Establish and Maintain a Secure Configuration Process for Network Infrastructure
  • CIS-4.6 Securely Manage Enterprise Assets and Software
  • CIS-4.7 Manage Default Accounts on Enterprise Assets and Software
  • CIS-4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
  • CIS-9.1 Ensure Use of Only Fully Supported Browsers and Email Clients
  • AM-2 Use only approved services
  • ASBv3-GS-5 Define and implement security posture management strategy
  • ASBv3-NS-7 Simplify network security configuration
  • ASBv3-NS-8 Detect and disable insecure services and protocols
  • ASBv3-PV-1 Define and establish secure configurations
  • ASBv3-PV-3 Define and establish secure configurations for compute resources
  • ASBv3-PV-4 Audit and enforce secure configurations for compute resources
  • PV-2 Audit and enforce secure configurations

NIST SP 800-218 · 7 controls

  • ISM-1406 Standard Operating Environments
  • ISM-1409 Hardening operating systems
  • ISM-1588 Annual review of Standard Operating Environments
  • ISM-1604 Hardening software-based isolation mechanisms
  • ISM-1913 Approved configurations for IT equipment
  • ISM-1914 Approved operating system configurations

CMMC 2.0 · 6 controls

  • ASD37-03 Configure Microsoft Office macro settings (Essential)
  • ASD37-04 User application hardening (Essential)
  • ASD37-09 OS generic exploit mitigation (Excellent)
  • ASD37-10 Server application hardening (Very Good)
  • ASD37-11 Operating system hardening (Very Good)

SOC 2 · 4 controls

  • SOC2-CC5.2 CC5.2 General controls over technology (COSO principle 11)
  • SOC2-CC7.1 CC7.1 Detecting configuration changes and new vulnerabilities
  • SOC2-CC8.1 CC8.1 Managing changes to procedures, software, data and infrastructure
  • SOC2-PI1.5 PI1.5 Controls over stored inputs, work in process and outputs
  • ANSSI-HYG-12 Change Default Authentication Elements on Equipment and Services
  • ANSSI-HYG-14 Apply a Minimum Security Level Across the Whole Estate
  • ANSSI-HYG-16 Use a Centralised Management Tool to Standardise Security Policies

C5 (Germany) · 3 controls

  • C5-DEV-03 Policies for changes to information systems
  • C5-OPS-23 Managing Vulnerabilities, Malfunctions and Errors - System Hardening
  • C5-PSS-11 Images for Virtual Machines and Containers

MTCS (Singapore) · 3 controls

  • 14.2 Server and network device configuration standards
  • 14.8 Unnecessary services and protocols
  • 24.5 Virtualisation

API 1164 · 2 controls

  • API1164-08 Configuration Management
  • API1164-22 Configuration management for OT systems

ETSI EN 303 645 · 2 controls

  • CJIS-5.7 Configuration Management
  • CJIS-7 Configuration Management

ISO 27001:2022 · 2 controls

  • 8.32 Change management
  • 8.9 Configuration management

NIST SP 800-128 · 2 controls

NIST SP 800-160 · 2 controls

NIST SP 800-161 Rev 1 · 2 controls

NIST SP 800-171 Rev 3 · 2 controls

NIST SP 800-172 · 2 controls

  • 3.14.4e Refresh Systems and Components from a Trusted Baseline
  • 3.4.2e Automated Detection and Remediation of Unauthorized Software

UK Cyber Essentials · 2 controls

  • CE-SC.1 Remove or Disable Unused Software
  • CE-SC.2 Change Default Passwords on Devices and Software
  • AUCDR-IS-2 Secure the network and systems within the data environment
  • AESCSF-ACM-2 Configuration management
  • SUP.8 Configuration Management
  • ITSG33-CM Configuration Management (CM)

DORA · 1 control

  • IS-V.A.2 Configuration Management

FedRAMP Rev 5 · 1 control

  • FEDRAMP-CM-1 Configuration Management Policy

IEC 62443 · 1 control

  • IEC62443-22 Configuration management for OT systems

ISO 10007:2017 · 1 control

  • 5.2 Configuration management planning
  • ISO-26262-8-7 Configuration management

ISO 27701:2019 · 1 control

  • ISO20000-10 Configuration management

ISO/IEC 27019:2024 · 1 control

  • ISO27019-22 Configuration management for OT systems

ISO/IEC 42001:2023 · 1 control

  • A.4 Resources for AI systems

ITIL 4 · 1 control

  • ITIL4-10 Configuration management
  • AQAP2110-4 Configuration Management and Change Control

NIS2 Directive · 1 control

  • Art.21.2.g Basic cyber hygiene practices and cybersecurity training

NIST SP 1800-32 · 1 control

  • 14.1.12.C.01 14.1.12.C.01 Characterise critical and high-risk servers
  • TSA-SD-12 Configuration and change management

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Technological controls – ISO 27002:2022

You are reading one control. How much of ISO 27002:2022 have you already done?

ISO 27002:2022 8.9 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of ISO 27002:2022 your existing evidence covers. Hold NIST SP 800-53 Rev 5 and 79 of 93 ISO 27002:2022 controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 180 were rejected on the NIST SP 800-53 Rev 5 pair alone.

Query this from an agent

The graph holds this control, the 200 it maps to, and the evidence behind each claim, over MCP and REST.