Skip to main content
Category: Technical Security Controls

Configuration Management Control (8.9)

Also known as: Annex A 8.9 Configuration Management, ISO 27002:2022 Control 8.9, Control 8.9
Simply put

Configuration Management is a control that asks an organization to set up, write down, and maintain secure settings for its hardware, software, services, and networks so they work correctly and safely. The goal is to reduce cyber risk by defining rules for how configurations are recorded, applied, and kept consistent over time. It is a preventative measure, meaning it aims to stop security problems before they occur rather than react to them after the fact.

Formal definition

In the ISO/IEC 27001:2022 revision, Configuration Management appears as Annex A control 8.9, a reference control detailed in ISO/IEC 27002:2022. It requires organizations to establish, document, implement, monitor, and review secure configurations for hardware, software, services, and networks, ensuring required security settings are defined and enforced and that configuration integrity is maintained over the system lifecycle. As an Annex A reference control, its applicability is determined through the risk assessment and Statement of Applicability rather than being automatically mandatory; the clause 4-10 ISMS requirements govern how it is selected and operated. Note that Annex A control counts and structure depend on the edition (the 2022 revision reorganized controls into four themes), so version should be specified when citing. This control addresses only the secure configuration domain and does not, on its own, guarantee freedom from breaches; coverage depends on the defined ISMS scope.

Why it matters

Configuration Management (Annex A control 8.9 in the ISO/IEC 27001:2022 revision) matters because misconfigured hardware, software, services, and networks are a common and preventable source of security weakness. When systems drift from their intended secure settings over time, gaps can emerge that expose an organization to cyber risk. Control 8.9 is framed as a preventative measure: it seeks to reduce that risk by establishing rules for how configurations are recorded, applied, and kept consistent, rather than reacting to problems after they surface.

The control addresses the reality that secure configuration is not a one-time task but a lifecycle concern. Settings that were correct at deployment can degrade through unmanaged changes, ad hoc fixes, or inconsistent standards across an estate. By requiring organizations to establish, document, implement, monitor, and review secure configurations, Control 8.9 aims to ensure that required security settings are defined and enforced and that configuration integrity is maintained over time.

It is important to keep the boundaries of this control in view. As an Annex A reference control, its applicability is determined through the organization's risk assessment and Statement of Applicability rather than being automatically mandatory. It also addresses only the secure configuration domain; on its own it does not guarantee freedom from breaches, and its coverage depends on the defined scope of the ISMS.

Who it's relevant to

Security engineers and system administrators
Those responsible for deploying and maintaining systems are typically closest to this control. They define and apply the required secure settings for hardware, software, services, and networks, and work to maintain configuration integrity over the system lifecycle so that drift from secure baselines is detected and corrected.
GRC and compliance managers
Professionals managing an ISO 27001 program need to determine, through the risk assessment and Statement of Applicability, whether and how control 8.9 applies to their ISMS. They document its selection and justification and ensure the control is monitored and reviewed in line with the clause 4-10 ISMS requirements.
Auditors and certification body assessors
Those assessing an ISMS against ISO/IEC 27001:2022 review how the organization establishes, documents, implements, monitors, and reviews secure configurations where control 8.9 has been selected. Because control structure and numbering depend on the edition, assessors should confirm which version is in scope when evaluating this control.

Inside Configuration Management Control (8.9)

Annex A Reference Control (ISO/IEC 27001:2022, A.8.9)
Configuration management appears as control 8.9 within the technological controls theme of Annex A in the 2022 revision of ISO/IEC 27001. As with all Annex A controls, it is a reference control selected for applicability through the Statement of Applicability and informed by risk assessment, rather than an unconditional requirement. Detailed implementation guidance for this control is typically found in ISO/IEC 27002:2022.
Configuration Definition and Baselines
The control concerns establishing, documenting, and maintaining configurations of hardware, software, services, and networks. This typically includes defining baseline or standard configurations against which systems can be compared, though the specific baselines depend on the organization's scope and risk decisions.
Implementation and Enforcement
Beyond defining configurations, the control addresses applying and enforcing configurations across in-scope systems, often through templates, hardening standards, or automated tooling. The approach taken varies by engagement and environment.
Monitoring and Review
The control encompasses ongoing monitoring and review of configurations to detect drift or unauthorized changes and to confirm that systems remain aligned with defined baselines over time, typically as part of the broader ISMS operation under clauses 4 through 10.
Relationship to Change Management
Configuration management is closely related to, but distinct from, change management. Configuration management concerns the state and baselines of systems, while change management governs how modifications are proposed, approved, and applied. In most environments the two work together.

Common questions

Answers to the questions practitioners most commonly ask about Configuration Management Control (8.9).

Is configuration management a control that ISO 27001 requires me to implement?
Not automatically. In the ISO/IEC 27001:2022 edition, configuration management appears as a reference control in Annex A (numbered 8.9 in that version). Annex A controls are not blanket mandates; they are selected through your risk assessment and documented in the Statement of Applicability. If your risk assessment justifies excluding it, that decision is recorded there. The certifiable requirements themselves live in clauses 4 through 10. Control counts and numbering depend on the edition, so this reference is specific to the 2022 revision.
Does having configuration management under ISO 27001 mean I also satisfy this area for a SOC 2 report?
Not directly. SOC 2 is an attestation examination performed by a licensed CPA firm under the AICPA's SSAE 18 standard against the Trust Services Criteria, while ISO 27001 is a certification issued by an accredited certification body against a management system standard. Configuration-related activities may map partially between the two, but satisfying one framework does not automatically satisfy the other. Mapping is possible but partial, and how a SOC 2 examination treats configuration activities depends on the criteria in scope and the auditor's judgment.
How should we document configurations to support this control?
Approaches vary by organization and scope, but many organizations maintain defined baseline configurations for their in-scope systems, record deviations, and keep those records current as systems change. The Statement of Applicability and supporting procedures typically describe how baselines are established, approved, and reviewed. There is no single prescribed format; certification bodies and auditors assess whether your approach is consistent with your documented risk decisions and operates as described.
How does configuration management relate to change management in an ISMS?
The two are commonly implemented together but address different concerns: configuration management typically focuses on defining and maintaining known-good baselines for systems, while change management governs how modifications are requested, approved, and applied. In many implementations, changes to a baseline flow through a change process, and the resulting configuration state is then recorded. How tightly these are coupled depends on your operating model and scope.
What evidence might an auditor or certification body look for regarding configuration management?
Expectations vary by the certification body or auditor and by scope, but assessors often look for evidence that baselines exist for in-scope systems, that configurations are reviewed periodically, and that deviations are identified and handled. In a SOC 2 Type II examination, an auditor typically evaluates operating effectiveness over the review period, so evidence spanning that period may be relevant; in a Type I engagement or an ISO 27001 assessment, the focus and evidence differ. The specific artifacts requested depend on the engagement.
What are the limitations of implementing this control?
Configuration management addresses a defined slice of security activity and does not, on its own, provide broad assurance. Within ISO 27001, any Annex A control operates in the context of the wider ISMS and the certificate covers only the defined scope of that ISMS. Within SOC 2, coverage of configuration-related activities is limited to the controls and period addressed in the report and does not guarantee freedom from breaches. Effectiveness also depends on keeping baselines current and on the surrounding processes, such as change management, functioning as intended.

Common misconceptions

Configuration Management (8.9) is a mandatory control that every ISO 27001-certified organization must implement.
Annex A controls are reference controls selected via the Statement of Applicability and informed by risk assessment. An organization may justify excluding a control if it is not applicable to its defined scope. The certifiable requirements are the ISMS clauses 4 through 10; Annex A controls such as 8.9 are applied depending on scope and risk decisions.
Because SOC 2 also addresses configuration, satisfying ISO 27001 control 8.9 automatically satisfies the corresponding SOC 2 expectations.
SOC 2 is an AICPA SSAE 18 attestation examination performed by a CPA firm and evaluated against the Trust Services Criteria, whereas ISO 27001 is a certification against a management system standard with Annex A reference controls. Mapping between the two is possible but partial, and meeting one framework does not automatically satisfy the other.
Control 8.9 is one of a fixed set of 114 Annex A controls.
Configuration management as a standalone control (8.9) reflects the 2022 revision of ISO/IEC 27001, in which Annex A was restructured into 93 controls organized under four themes. The earlier 2013 version listed 114 controls with a different structure. Any control number or count should be stated with reference to the specific edition.

Best practices

Confirm whether control 8.9 is applicable to your defined ISMS scope and record the decision and its justification in the Statement of Applicability, driven by your risk assessment.
Cite the specific ISO/IEC 27001 edition (2022) when referencing control 8.9, since control numbers and the overall Annex A structure differ between the 2013 and 2022 revisions.
Consult ISO/IEC 27002:2022 for detailed implementation guidance on configuration management, keeping in mind it provides guidance rather than certifiable requirements.
Define and document baseline configurations for in-scope hardware, software, services, and networks, and establish a means to compare live systems against those baselines.
Coordinate configuration management with your change management process so that approved changes are reflected in updated baselines and unauthorized drift can be identified.
Establish periodic monitoring and review of configurations to detect deviations, and retain evidence of these reviews to support both the ISMS and any related audit or attestation activity, recognizing that a certificate covers only the defined scope of the ISMS.