Configuration Management Control (8.9)
Configuration Management is a control that asks an organization to set up, write down, and maintain secure settings for its hardware, software, services, and networks so they work correctly and safely. The goal is to reduce cyber risk by defining rules for how configurations are recorded, applied, and kept consistent over time. It is a preventative measure, meaning it aims to stop security problems before they occur rather than react to them after the fact.
In the ISO/IEC 27001:2022 revision, Configuration Management appears as Annex A control 8.9, a reference control detailed in ISO/IEC 27002:2022. It requires organizations to establish, document, implement, monitor, and review secure configurations for hardware, software, services, and networks, ensuring required security settings are defined and enforced and that configuration integrity is maintained over the system lifecycle. As an Annex A reference control, its applicability is determined through the risk assessment and Statement of Applicability rather than being automatically mandatory; the clause 4-10 ISMS requirements govern how it is selected and operated. Note that Annex A control counts and structure depend on the edition (the 2022 revision reorganized controls into four themes), so version should be specified when citing. This control addresses only the secure configuration domain and does not, on its own, guarantee freedom from breaches; coverage depends on the defined ISMS scope.
Why it matters
Configuration Management (Annex A control 8.9 in the ISO/IEC 27001:2022 revision) matters because misconfigured hardware, software, services, and networks are a common and preventable source of security weakness. When systems drift from their intended secure settings over time, gaps can emerge that expose an organization to cyber risk. Control 8.9 is framed as a preventative measure: it seeks to reduce that risk by establishing rules for how configurations are recorded, applied, and kept consistent, rather than reacting to problems after they surface.
The control addresses the reality that secure configuration is not a one-time task but a lifecycle concern. Settings that were correct at deployment can degrade through unmanaged changes, ad hoc fixes, or inconsistent standards across an estate. By requiring organizations to establish, document, implement, monitor, and review secure configurations, Control 8.9 aims to ensure that required security settings are defined and enforced and that configuration integrity is maintained over time.
It is important to keep the boundaries of this control in view. As an Annex A reference control, its applicability is determined through the organization's risk assessment and Statement of Applicability rather than being automatically mandatory. It also addresses only the secure configuration domain; on its own it does not guarantee freedom from breaches, and its coverage depends on the defined scope of the ISMS.
Who it's relevant to
Inside Configuration Management Control (8.9)
Common questions
Answers to the questions practitioners most commonly ask about Configuration Management Control (8.9).