The organization is to set, record, apply, watch and review how its hardware, software, services and networks are configured, security settings included. Purpose: keep hardware, software, services and networks working correctly with the security settings they need, and keep settings from being altered without approval or by mistake. Guidance: define and run processes and tools that enforce defined configurations for hardware, software, services such as cloud services, and networks, both on new installations and through the life of operational systems, with roles, responsibilities and procedures that keep every configuration change under control. Standard secure configuration templates should draw on public guidance such as vendor and independent security organization baselines, reflect the protection level needed, support the organization's policies and standards, and be feasible in its context; review them periodically and update them for new threats, vulnerabilities or new software and hardware versions. Templates should consider: keeping the number of privileged or administrator identities low; disabling unnecessary, unused or insecure identities; disabling or restricting unneeded functions and services; restricting access to powerful utilities and host parameters; clock synchronization; changing vendor default credentials immediately after installation and reviewing other security-relevant defaults; inactivity timeouts that log devices off; and checking licence compliance (5.32). Managing: record established configurations and log every change, stored securely, for example in a configuration database or templates, with changes going through change management (8.32); records can hold the current owner or contact, date of last change, template version and links to related assets' configurations. Monitoring: use a broad range of system management tooling (maintenance utilities, remote support, enterprise management, backup and restore) and review regularly to check settings, evaluate password strength and assess activity; compare actual settings with target templates and correct deviations by automatic enforcement or by manual analysis and corrective action. Other information: system documentation often holds configuration detail; hardening is part of configuration management; it can be joined with asset management; automation such as infrastructure as code is usually more effective; templates and targets can be confidential and should be protected.
This control maps to 200 controls across 53 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
ISO 27002:2022 8.9 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of ISO 27002:2022 your existing evidence covers. Hold NIST SP 800-53 Rev 5 and 79 of 93 ISO 27002:2022 controls already carry evidence.
Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 180 were rejected on the NIST SP 800-53 Rev 5 pair alone.
The graph holds this control, the 200 it maps to, and the evidence behind each claim, over MCP and REST.