ISO/IEC 27000 Configuration Management, v2022
Specifies requirements in accordance with the security and privacy controls specified by ISO/IEC Publication 27001:2022, related to configuration management.
Assessment Step
|
1
Configuration Management (ConfigurationManagement)
Are configurations - including security configurations - of hardware, software, services, and networks established, documented, implemented, monitored, and reviewed?
Artifact
A1
Provide evidence (e.g. organizational policies, procedures, compliance/assessment reports, etc.) and supporting notes as appropriate to support the assessor's response to this assessment step.
|
Conformance Criteria (1)
|
Configuration Management
Configurations, including security configurations, of hardware, software, services and networks shall be established, documented, implemented, monitored and reviewed.
Citations
27001
Annex A, Control 8.9
27002
Section 8.9
|