ISO 27001 A.8.9 — Configuration management
A.8.9 asks you to define secure configurations, apply them, and notice when they change. It is the control that turns 'we set it up securely' into something you can prove twelve months later.
A.8.9 asks you to define secure configurations, apply them, and notice when they change. It is the control that turns 'we set it up securely' into something you can prove twelve months later.
Configurations, including security configurations, of hardware, software, services and networks shall be established, documented, implemented, monitored and reviewed. That covers laptops, servers, cloud tenants, network devices and applications.
Theme: Technological · New in ISO 27001:2022
Configuration drift is invisible until it is exploited. A documented baseline gives you a reference point: without it, nobody can say whether a setting was always wrong or was changed last Tuesday.
Use the tooling you already pay for. Intune or Jamf baselines for endpoints, Microsoft Secure Score or your cloud provider's posture tooling for the tenant, and a short written baseline for anything managed by hand.
See the full list of all 93 Annex A controls or start from the Statement of Applicability template.
ISO-STANDARD.app ships all 93 Annex A controls pre-loaded, linked to your risks, evidence and owners — with an AI 'Fix this' plan for anything failing.
ISO-STANDARD.app ships a ready-to-adopt ISO 27001 workspace with the risk register, controls catalogue, policies and audit-ready exports already wired together — no spreadsheet sprawl, no consultant lock-in.
Prefer a conversation? Email hello@iso-standard.app — a real human responds within one business day.