ISO/IEC 27000 Configuration Management, v2022
Specifies requirements in accordance with the security and privacy controls specified by ISO/IEC Publication 27001:2022, related to configuration management.
Assessment Step
1
Configuration Management (ConfigurationManagement)
Are configurations - including security configurations - of hardware, software, services, and networks established, documented, implemented, monitored, and reviewed?
Artifact
A1
Provide evidence (e.g. organizational policies, procedures, compliance/assessment reports, etc.) and supporting notes as appropriate to support the assessor's response to this assessment step.
|
Conformance Criteria (1)
Configuration Management
Configurations, including security configurations, of hardware, software, services and networks shall be established, documented, implemented, monitored and reviewed.
Citations
27001
Annex A, Control 8.9
27002
Section 8.9
|