ISO 27001 A.8.9 — Configuration management

A.8.9 asks you to define secure configurations, apply them, and notice when they change. It is the control that turns 'we set it up securely' into something you can prove twelve months later.

Michael McCarroll 6 min read Updated August 2026

What the control says

Configurations, including security configurations, of hardware, software, services and networks shall be established, documented, implemented, monitored and reviewed. That covers laptops, servers, cloud tenants, network devices and applications.

Theme: Technological · New in ISO 27001:2022

Why it matters

Configuration drift is invisible until it is exploited. A documented baseline gives you a reference point: without it, nobody can say whether a setting was always wrong or was changed last Tuesday.

Use the tooling you already pay for. Intune or Jamf baselines for endpoints, Microsoft Secure Score or your cloud provider's posture tooling for the tenant, and a short written baseline for anything managed by hand.

How to implement it

  1. List the asset types that need a baseline: laptops, mobile devices, servers, cloud tenants, network equipment, and any key application.
  2. Adopt a recognised starting point (CIS Benchmarks, Microsoft security baselines, vendor hardening guides) instead of writing baselines from scratch.
  3. Record deliberate deviations with a reason and an approver — auditors accept documented exceptions, not undocumented ones.
  4. Deploy the baselines via management tooling so new devices inherit them automatically.
  5. Monitor for drift: compliance reports from Intune/Jamf, posture scores, or a periodic manual check for hand-managed kit.
  6. Review baselines at least annually and after any significant platform change.

Evidence auditors ask for

  • Documented baselines per asset type, with version and approval date
  • Deployment evidence — device compliance reports or configuration profiles
  • Drift or non-compliance reports plus what was done about the exceptions
  • Exception register with reason, approver and review date
  • Change records for baseline updates

Common findings

  • Baselines documented but never applied — the policy says one thing, the device report says another.
  • No coverage of cloud tenant configuration, only endpoints.
  • Non-compliant devices visible in reports for months with no corrective action.
  • Exceptions granted verbally, with nothing written down.

Related controls

See the full list of all 93 Annex A controls or start from the Statement of Applicability template.

FAQ

Do we need a CMDB for A.8.9?
No. A configuration management database helps at scale, but the control requires documented, applied and monitored configurations. For most SMEs that is device management policies plus a short baseline document.
Can we use CIS Benchmarks as our baseline?
Yes, and it is the fastest route. Adopt the benchmark, document which level you apply, and record any deviations you need for operational reasons.
How does A.8.9 differ from A.8.32 change management?
A.8.9 defines what 'correct' looks like and detects drift from it. A.8.32 governs how approved changes are made. They work as a pair: change management moves the baseline, configuration management proves the estate matches it.

Evidence A.8.9 without the spreadsheet

ISO-STANDARD.app ships all 93 Annex A controls pre-loaded, linked to your risks, evidence and owners — with an AI 'Fix this' plan for anything failing.

ISO-STANDARD.app ships a ready-to-adopt ISO 27001 workspace with the risk register, controls catalogue, policies and audit-ready exports already wired together — no spreadsheet sprawl, no consultant lock-in.

Free downloads for this topic

Prefer a conversation? Email hello@iso-standard.app — a real human responds within one business day.

Related guides
Trust & security
ISO 27001 aligned
Controls mapped to Annex A
Encryption in transit & at rest
TLS 1.3 · AES-256
MFA enforced
TOTP required for all admins
GDPR & UK GDPR
DPA on request · EU/UK data
SOC 2 ready posture
Audit-grade logging
RLS-isolated tenants
Row-level data separation
← All guidesHome →