Secure Configuration
What is Secure Configuration?
The process of implementing security settings and hardening measures on systems and devices according to established security baselines and benchmarks.
Terms that appear alongside secure configuration
Each of these is named in at least one of the same controls as secure configuration. The number is how many controls name both.
- hardening 13 shared controls
- cybersecurity 11 shared controls
- baseline 9 shared controls
- integrity 7 shared controls
- access control 7 shared controls
- vulnerability 6 shared controls
- network segmentation 6 shared controls
- cis benchmarks 6 shared controls
Frameworks that govern secure configuration
What the standards actually require on secure configuration
Requirements naming secure configuration across 6 standards, quoted from the control text.
Establish secure configuration settings that reflect the most restrictive mode consistent with operational requirements.
SP800-128-SECURE-CONFIG · Secure Configurations of Information Systems →Use Azure Policy and Defender for Cloud secure score to audit and enforce configuration baselines across subscriptions.
PV-2 · Audit and enforce secure configurations →Establish and maintain a secure configuration process for network devices. Review and update documentation annually, or when significant enterprise changes occur that could impact this Safeguard.
CIS-4.2 · Establish and Maintain a Secure Configuration Process for Network Infrastructure →Systems must be deployed using secure configurations, unnecessary services and ports must be disabled, and baselines must be maintained.
DEFSTAN-CONFIG · Secure Configuration and Hardening →UR E27 requires equipment manufacturers to deliver hardened CBS with secure default configuration + secure communications. Hardening: minimum services + disabled debug + locked BIOS + secure boot + Trusted Platform Module (TPM) or equivalent root of trust + si...
IACS-UR-E27-Equipment-Hardening-SecureConfig-Communications · IACS UR E27 - Equipment Hardening + Secure Configuration + Secure Communications + Cryptography →Secure configuration guidance, in the form of a hardening guide or loosening guide, is produced and made available to consumers as part of software development.
ISM-1798 · Secure configuration guidance, in the form of a hardening guide or loosening guide, is pro →Questions people ask about secure configuration
What is Secure Configuration?
Why is Secure Configuration important for compliance?
Which compliance frameworks address Secure Configuration?
Where can I learn more about Secure Configuration?
See how Secure Configuration applies across compliance frameworks
Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.