A.8.9Configuration management
Establish, document and maintain secure configurations for your hardware, software and services, and detect drift away from them over time.
A.8.9 is covered by 46 Sekit CSF controls. +41 more in the table below. Open in the full graph →
Mapped from the Sekit CSF
The Sekit controls that cover this requirement, lens by lens.
NIST CSF 2.0 counterparts
Reached through the Sekit CSF controls both map to — a mapping, not a formal equivalence.
ISO/IEC 42001:2023 — Annex A counterparts
Cyber Essentials counterparts
Evidence that proves this control
What an auditor, or Sekit's evidence engine, asks for.
In practice
Configuration baselines usually exist as a document from when devices were first standardized, and drift takes over from there. An SME might show a hardened laptop image, but the RMM console reveals a meaningful share of the fleet has drifted from it: a disabled firewall rule here, a browser extension there. Cloud configuration is worse: the CSPM tool flags dozens of findings on day one because default settings were never reviewed against a written baseline, only against whatever the vendor shipped, and production changes still slip in outside the ticketed process whenever an incident makes the approval step feel like an obstacle.
Common gaps
Questions your auditor will ask
Where regulation demands it
Related controls
Via the shared Sekit CSF topic, not the framework's own index.