ISO 27001 Annex A 8.9Configuration Management for Secure IT Systems
Official control statement
Configurations, including security configurations, of hardware, software, services and networks shall be established, documented, implemented, monitored and reviewed.
Quoted as published. Everything else on this page is written by Control Stack.
In plain English
Set and keep secure settings for all IT systems and watch for changes.
What this means in practice
Configuration management ensures that all the settings for your computers, software, and networks are planned and kept secure, reducing the chance of unexpected changes that could lead to security problems. Without this, systems can become vulnerable to attacks or operate inefficiently due to unauthorised or incorrect changes.
Framework
ISO/IEC 27001:2022
Control effect (Control Stack)
Preventative
ISO 27001 domain
Technological controls
Classifications
N/A
Official last update
24 Oct 2022
Control Stack last updated
30 Sept 2026
Why it matters
Poor configuration management leaves systems open to attacks and operational errors, risking company data and service disruptions.
Operational notes
Regularly monitor systems for baseline compliance and adjust settings when introducing new technology to prevent drift and minimise risks.
Implementation tips
- The IT manager should set up standard settings (often called baselines) for all hardware and software. Use trusted guides from vendors or security organisations to set these templates, and ensure they''re documented as per Australian regulations.
- System administrators must regularly check these configurations. Use tools to compare current settings against your standard ones, and fix any discrepancies promptly to prevent security risks.
- The security team should have procedures for managing changes. Only make adjustments to configurations through a formal process to avoid mistakes and unauthorised changes, aligning with ISO 27002:2022 guidance.
- HR and IT should ensure the right people have the right access. Limit access to system settings and disable any unnecessary admin rights to protect against misuse according to the ASD Essential Eight strategies.
- The IT team must ensure systems'' clocks are synchronised and unnecessary functions are disabled. This helps in maintaining system integrity and ensuring audit logs are accurate and reliable.
Audit / evidence tips
- AskAsk for the configuration baselines and standard templates used for hardware, software, services and networks.Look atLook at whether the documentation is complete, current and relevant to the systems actually in use, and whether the settings are drawn from trusted sources.GoodA good answer includes well-documented baselines and templates that are based on trusted sources and cover the security configurations of each system type.
- AskRequest a log of configuration changes made to systems and networks.Look atExamine whether each recorded change followed the organisation's change management process, including approval before implementation.GoodA good answer shows detailed change logs where each configuration change is linked to an approved change request.
- AskAsk about the tools used to monitor configurations and ask for a demonstration of how they are set up.Look atInspect the tool configuration to verify that settings are checked against the documented baselines on a regular basis.GoodA good setup detects deviations from the baseline and traces each identified deviation back to a corrective action.
- AskAsk for records of access rights to the systems whose configurations are managed.Look atCheck that access to change configurations is restricted in line with the documented security requirements.GoodGood implementation shows that only the personnel who need it hold access, and that access is limited to what their role requires.
- AskRequest the system clock synchronisation settings for in-scope systems.Look atConfirm that all systems are synchronised to a consistent time source as part of the documented configuration.GoodA well-synchronised environment produces consistent timestamps in logs, which supports monitoring and review of configurations.
Cross-framework mappings
How Annex A 8.9 relates to controls across ISO/IEC 27001, ISO/IEC 42001, Essential Eight, and ASD ISM.
E8
| Control | Notes | Details |
|---|---|---|
open_in_fullBroader than(6)expand_less | ||
extensionDepends on(1)expand_less | ||
ASD ISM
| Control | Notes | Details |
|---|---|---|
equalEquivalent(1)expand_less | ||
| ISM-1913 | ISM-1913 requires approved configurations for IT equipment to be developed, implemented and maintained | |
open_in_fullBroader than(62)expand_less | ||
| ISM-0272 | ISM-0272 requires a secure configuration outcome: protective marking tools must not allow markings beyond the system's authorised classif... | |
| ISM-0341 | ISM-0341 requires automatic execution features for removable media to be disabled to prevent code running when media is inserted | |
| ISM-0380 | ISM-0380 requires unneeded operating system user accounts, components, services and functionality to be disabled or removed to reduce att... | |
| ISM-0383 | ISM-0383 requires default operating system user accounts and credentials (including pre-configured accounts) to be changed, disabled or r... | |
| ISM-0484 | ISM-0484 requires specific secure configuration settings for the SSH daemon, such as interface binding and authentication timeouts | |
| ISM-0487 | ISM-0487 requires specific security configurations for SSH in passwordless scenarios, including disabling forwarding and limiting access ... | |
| ISM-0498 | ISM-0498 requires organisations to configure IPsec security association (SA) lifetimes to less than four hours to limit cryptographic exp... | |
| ISM-0567 | ISM-0567 requires email servers to be configured so they only relay emails destined for or originating from the organisation's own domain... | |
| ISM-0570 | ISM-0570 requires that any backup or alternative email gateways are maintained to the same security and operational standard as the prima... | |
| ISM-0864 | ISM-0864 requires mobile devices to lock down security settings so users cannot disable or modify security functionality after provisioning | |
| ISM-1027 | ISM-1027 requires organizations to configure email distribution list applications used by external senders to ensure the sender's DKIM si... | |
| ISM-1037 | ISM-1037 requires gateways to be tested after configuration changes and at least every six months to confirm they conform to expected sec... | |
| ISM-1055 | ISM-1055 requires a specific security configuration: disabling LAN Manager and NT LAN Manager authentication methods | |
| ISM-1183 | ISM-1183 requires an organisation to publish and use hard fail SPF DNS records to specify which email servers are authorised to send for ... | |
| ISM-1196 | ISM-1196 mandates a specific security configuration state for mobile devices: Bluetooth must be undiscoverable except during pairing | |
| ISM-1260 | ISM-1260 requires default server application accounts and credentials to be changed, disabled or removed as part of initial setup | |
| ISM-1272 | ISM-1272 requires a specific configuration state for database servers, where the DBMS is set to not accept remote connections unless need... | |
| ISM-1304 | ISM-1304 demands that default accounts or credentials on network devices be changed, disabled, or removed at initial setup | |
| ISM-1311 | ISM-1311 mandates that organisations ensure SNMP version 1 and 2 are not used on networks | |
| ISM-1312 | ISM-1312 requires a specific secure configuration outcome for SNMP on network devices (non-default community strings and no write access) | |
| ISM-1316 | ISM-1316 requires that default SSIDs are changed on wireless access points as part of secure configuration | |
| ISM-1319 | ISM-1319 requires organisations to avoid static IP addressing on wireless networks as a specific configuration choice to reduce risk | |
| ISM-1406 | ISM-1406 requires organisations to use SOEs for workstations and servers to ensure consistent, secure configurations | |
| ISM-1408 | ISM-1408 requires organisations to use 64-bit versions of operating systems | |
| ISM-1409 | ISM-1409 requires organisations to implement hardened operating system configurations using ASD and vendor guidance, applying the most re... | |
| ISM-1428 | ISM-1428 mandates a specific secure configuration setting: IPv6 tunnelling is disabled unless needed | |
| ISM-1489 | ISM-1489 requires Microsoft Office macro security settings to be centrally enforced and locked against user changes | |
| ISM-1562 | ISM-1562 requires hardening of video conferencing and IP telephony infrastructure through secure configurations | |
| ISM-1585 | ISM-1585 requires web browser security settings to be centrally enforced such that human users cannot change them | |
| ISM-1588 | ISM-1588 requires organisations to review and update Standard Operating Environments (SOEs) at least annually | |
| ISM-1598 | ISM-1598 requires IT equipment to be inspected after maintenance or repair to confirm it still matches the approved configuration and has... | |
| ISM-1604 | ISM-1604 requires a hardened configuration for the software-based isolation mechanism, including removing unneeded functionality and rest... | |
| ISM-1605 | ISM-1605 requires that the underlying operating system for software-based isolation on shared servers is hardened, which relies on establ... | |
| ISM-1622 | ISM-1622 mandates a particular security configuration for a specific technology (PowerShell Constrained Language Mode) | |
| ISM-1669 | ISM-1669 requires Microsoft Office to be blocked from injecting code into other processes | |
| ISM-1673 | ISM-1673 requires implementing a specific security configuration: blocking Win32 API calls from Microsoft Office macros | |
| ISM-1710 | ISM-1710 requires wireless access points to be hardened by changing insecure default settings and applying secure configuration | |
| ISM-1806 | ISM-1806 requires default user accounts and credentials in user applications to be changed, disabled, or removed during initial setup | |
| ISM-1823 | ISM-1823 requires locking down office productivity suite security settings so users cannot change them | |
| ISM-1824 | ISM-1824 requires preventing user changes to PDF application security settings, ensuring a fixed secure configuration for that application | |
| ISM-1825 | ISM-1825 requires that users cannot change the security settings of security products, preserving the intended secure state | |
| ISM-1828 | ISM-1828 requires the Print Spooler service to be disabled specifically on Microsoft AD DS domain controllers to reduce attack surface | |
| ISM-1832 | ISM-1832 requires that only service accounts and computer accounts are configured with Service Principal Names (SPNs) in Active Directory | |
| ISM-1834 | ISM-1834 requires organisations to maintain a correct Active Directory configuration state by preventing or remediating duplicate SPNs, w... | |
| ISM-1838 | ISM-1838 requires a specific security configuration outcome in AD: the UserPassword attribute for user accounts is not used | |
| ISM-1860 | ISM-1860 requires hardening of PDF applications using ASD and vendor guidance, prioritising the most restrictive settings | |
| ISM-1887 | ISM-1887 requires a particular security configuration on mobile devices: remote locate and wipe must be enabled and usable | |
| ISM-1888 | ISM-1888 requires a specific security configuration on mobile devices: secure lock screens | |
| ISM-1914 | Annex A 8.9 requires secure configurations to be established and managed across IT systems | |
| ISM-1915 | ISM-1915 requires approved configurations for user applications to be developed, implemented, and maintained | |
| ISM-1916 | Annex A 8.9 requires secure configurations to be established, documented, implemented, monitored and reviewed across IT assets | |
| ISM-1926 | ISM-1926 mandates a hardened configuration baseline for AD-related servers by restricting them to their designed roles | |
| ISM-1931 | ISM-1931 requires SID Filtering to be enabled on domain and forest trusts to prevent abuse of SIDHistory/foreign SIDs across trust bounda... | |
| ISM-1935 | ISM-1935 mandates that Active Directory computer accounts are not configured for unconstrained delegation, a specific security measure to... | |
| ISM-1944 | ISM-1944 requires a specific secure configuration on Microsoft AD CS certification authorities by removing the EDITF_ATTRIBUTESUBJECTALTN... | |
| ISM-1951 | ISM-1951 requires a specific security configuration: hard match takeover must be disabled on Microsoft Entra Connect servers | |
| ISM-2127 | ISM-2127 requires the operating system to enforce kernel-mode driver digital signature verification before any driver is loaded and to pr... | |
| ISM-2130 | ISM-2130 requires organisations to disable AD CS web enrolment interfaces unless required, and if enabled, to harden them by enforcing HT... | |
| ISM-2131 | ISM-2131 requires certificate templates to be reviewed at least quarterly to identify and remediate misconfigurations that could enable p... | |
| ISM-2161 | ISM-2161 requires comparing network device firmware and running configurations to a known-good baseline on a defined schedule and after r... | |
| ISM-2162 | ISM-2162 requires disabling or removing unneeded network device components and services as a secure configuration outcome | |
| ISM-2167 | ISM-2167 requires organisations to disable MACsec's Pre-Shared Key (PSK) fallback authentication so links cannot silently downgrade to a ... | |
layersPartially meets(1)expand_less | ||
| ISM-1211 | ISM-1211 requires system administrators to carry out system administration activities in line with an established change and configuratio... | |
sync_altPartially overlaps(8)expand_less | ||
| ISM-0042 | ISM-0042 requires organisations to develop, implement and maintain effective system administration practices and procedures for managing ... | |
| ISM-0289 | ISM-0289 requires evaluated products to be installed, configured, administered and operated in an evaluated configuration and in accordan... | |
| ISM-0290 | ISM-0290 requires high assurance IT equipment to be installed, configured, administered and operated in an evaluated configuration and in... | |
| ISM-0518 | ISM-0518 requires organisations to keep network documentation current and available | |
| ISM-0589 | ISM-0589 requires controlling MFD configuration and use so higher-classified material is not scanned/copied on lower-classified networks | |
| ISM-0912 | Annex A 8.9 requires configurations of hardware, software, services and networks to be established, documented, implemented, monitored an... | |
| ISM-1608 | ISM-1608 requires third-party SOEs to be checked for insecure or non-compliant configurations (as well as malicious code) before they are... | |
| ISM-1912 | Annex A 8.9 requires organisations to document and maintain configurations for systems and to keep them under review | |
handshakeSupports(2)expand_less | ||
| ISM-0516 | ISM-0516 requires network documentation to include high-level and logical network diagrams showing all connections and all critical compo... | |
| ISM-1798 | ISM-1798 requires publishing secure configuration guidance so consumers can securely configure the software | |
extensionDepends on(2)expand_less | ||
| ISM-1552 | ISM-1552 requires organisations to configure web applications and associated services so content is delivered only via HTTPS | |
| ISM-1627 | ISM-1627 requires inbound network connections from anonymity networks to be blocked | |
These mappings show relationships between controls across frameworks. They do not imply full equivalence or certification.
Related ISO 27001 controls in Technological controls
See all Technological controls controls, or browse the full ISO 27001 Annex A library. You can also track all 93 controls with the free ISO 27001 Annex A checklist.
Want to implement this control?
Mindset Cyber runs PECB-accredited ISO/IEC 27001 training that maps directly to the controls in this library.