A.8.9
    Technological Controls

    Configuration management

    Configurations, including security configurations, of hardware, software, services and networks should be established, documented, implemented, monitored and reviewed.

    Purpose

    To establish and maintain secure configurations of systems.

    Implementation Guidance

    Document configuration standards and baselines

    Implement configuration management tools

    Monitor configuration drift

    Review configurations regularly

    Control changes to configurations

    Recommended Tools

    ISO 27001 Services from the Directory

    These providers can help you implement A.8.9 and achieve ISO 27001 certification.

    By the team behind ISMS Directory

    Implementing A.8.9 for a client?

    ISMS Copilot drafts policies, evidence, and SoA wording for A.8.9 Configuration management. Built for compliance professionals.

    Try ISMS Copilot free